VendorsPalo Alto Networksglobalprotectall versions
Vulnerabilities

Palo Alto Networks GlobalProtect

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2021-3057
GlobalProtect App: Buffer Overflow Vulnerability When Connecting to Portal or Gateway
Published 2021-10-13 · Modified
9.3EPSS 0.014
CVE-2024-5921
GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation
Published 2024-11-27 · Analyzed
8.8EPSS 0.015
CVE-2025-4232
GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
Published 2025-06-12 · Analyzed
8.8EPSS 0.004
CVE-2026-0250
GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway
Published 2026-05-13 · Analyzed
8.1EPSS 0.004
CVE-2026-0298
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Published 2026-08-13 · Undergoing Analysis
8.1EPSS 0.003
CVE-2026-0297
GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
Published 2026-08-13 · Undergoing Analysis
8.1EPSS 0.003
CVE-2025-0118
GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability
Published 2025-03-12 · Analyzed
8.0EPSS 0.004
CVE-2024-9473
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Published 2024-10-09 · Modified
7.8EPSS 0.003
CVE-2022-0017
GlobalProtect App: Improper Link Resolution Vulnerability Leads to Local Privilege Escalation
Published 2022-02-10 · Modified
7.8EPSS 0.003
CVE-2020-1989
Global Protect Agent: Incorrect privilege assignment allows local privilege escalation
Published 2020-04-08 · Modified
7.8EPSS 0.003
CVE-2024-5915
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.002
CVE-2022-0016
GlobalProtect App: Privilege Escalation Vulnerability When Using Connect Before Logon
Published 2022-02-10 · Modified
7.8EPSS 0.002
CVE-2026-0299
GlobalProtect App: Local Privilege Escalation Vulnerabilities
Published 2026-08-13 · Analyzed
7.8EPSS 0.002
CVE-2026-0251
GlobalProtect App: Local Privilege Escalation Vulnerabilities
Published 2026-05-13 · Analyzed
7.8EPSS 0.002
CVE-2023-0009
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Published 2023-06-14 · Modified
7.8EPSS 0.002
CVE-2024-3661
DHCP routing options can manipulate interface-based VPN traffic
Published 2024-05-06 · Analyzed
7.6EPSS 0.041
CVE-2024-5908
GlobalProtect App: Encrypted Credential Exposure via Log Files
Published 2024-06-12 · Modified
7.5EPSS 0.004
CVE-2026-0296
GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Published 2026-08-13 · Undergoing Analysis
7.4EPSS 0.001
CVE-2017-15870
Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking."
Published 2017-12-11 · Modified
7.2EPSS 0.004
CVE-2020-1988
Global Protect Agent: Local privilege escalation due to an unquoted search path vulnerability
Published 2020-04-08 · Modified
7.2EPSS 0.004
CVE-2024-8687
PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes
Published 2024-09-11 · Analyzed
7.1EPSS 0.004
CVE-2019-17436
A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12 and earlier, that can allow non-root users to overwrite root files on the file system.
Published 2019-10-16 · Modified
7.1EPSS 0.003
CVE-2025-0120
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Published 2025-04-11 · Analyzed
7.1EPSS 0.002
CVE-2024-2432
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Published 2024-03-13 · Analyzed
7.0EPSS 0.004
CVE-2020-2032
GlobalProtect App: File race condition vulnerability leads to local privilege escalation during upgrade
Published 2020-06-10 · Modified
7.0EPSS 0.002
CVE-2026-0295
GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
Published 2026-08-13 · Analyzed
7.0EPSS 0.001
CVE-2020-2004
GlobalProtect App: Passwords may be logged in clear text while collecting troubleshooting logs
Published 2020-05-13 · Modified
6.8EPSS 0.003
CVE-2022-0018
GlobalProtect App: Information Exposure Vulnerability When Connecting to GlobalProtect Portal With Single Sign-On Enabled
Published 2022-02-10 · Modified
6.5EPSS 0.007
CVE-2026-0249
GlobalProtect App: Certificate Validation Bypass Vulnerabilities
Published 2026-05-13 · Analyzed
6.5EPSS 0.001
CVE-2023-0006
GlobalProtect App: Local File Deletion Vulnerability
Published 2023-04-12 · Modified
6.3EPSS 0.001
CVE-2012-6606
Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.
Published 2013-08-31 · Modified
5.8EPSS 0.008
CVE-2019-17435
A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for Windows 4.1.12 and earlier, in which the auto-update feature can allow for modification of a GlobalProtect Agent MSI installer package on disk before installation.
Published 2019-10-16 · Modified
5.5EPSS 0.003
CVE-2020-1976
GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.
Published 2020-02-12 · Modified
5.5EPSS 0.003
CVE-2022-0021
GlobalProtect App: Information Exposure Vulnerability When Using Connect Before Logon
Published 2022-02-10 · Modified
5.5EPSS 0.002
CVE-2021-3038
GlobalProtect App: Windows VPN kernel driver denial of service (DoS)
Published 2021-04-20 · Modified
5.5EPSS 0.002
CVE-2022-0019
GlobalProtect App: Insufficiently Protected Credentials Vulnerability on Linux
Published 2022-02-10 · Modified
5.5EPSS 0.002
CVE-2024-2431
GlobalProtect App: Local User Can Disable GlobalProtect
Published 2024-03-13 · Analyzed
5.5EPSS 0.002
CVE-2026-0267
GlobalProtect App: Information Exposure Vulnerability on macOS
Published 2026-06-10 · Analyzed
5.5EPSS 0.001
CVE-2020-2033
GlobalProtect App: Missing certificate validation vulnerability can disclose pre-logon authentication cookie
Published 2020-06-10 · Modified
5.3EPSS 0.009
CVE-2025-0135
GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App
Published 2025-05-14 · Analyzed
5.2EPSS 0.001
1 / 2Next →