Palo Alto Networks globalprotect app是美国Palo Alto Networks公司的一款终端安全反病毒软件。 Palo Alto Networks globalprotect app 6.0.15之前版本、6.2.8-h13之前版本和6.3.5之前版本存在缓冲区错误漏洞,该漏洞源于缓冲区溢出,可能导致中间人攻击者或恶意网关破坏系统进程并可能利用提升的权限执行任意代码(在Windows上为SYSTEM权限,在macOS和Linux上为root权限)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | 6.3.0< 6.3.3-h15 |
affected |
6.2.0 |
affected | ||
6.0.0< 6.0.15 |
affected | ||
6.3.0< 6.3.3-h14 |
affected | ||
6.2.0< 6.2.8-h13 |
affected | ||
6.0.0< 6.0.15 |
affected | ||
6.3.0< 6.3.5 |
affected | ||
6.0.0< 6.0.15 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | 6.3.0 ~ 6.3.3-h15 |
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:Linux:*:*
|
|
| Palo Alto Networks | GlobalProtect App | 6.3.0 ~ 6.3.3-h14 |
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:macOS:*:*
|
|
| Palo Alto Networks | GlobalProtect App | 6.3.0 ~ 6.3.5 |
cpe:2.3:a:palo_alto_networks:globalprotect_app:6.3.3:*:*:*:*:iOS:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0294 | 6.0 MEDIUM | Prisma Access Agent: Local Privilege Escalation |
| CVE-2026-0299 | 5.9 MEDIUM | GlobalProtect App: Local Privilege Escalation Vulnerabilities |
| CVE-2026-0293 | 5.6 MEDIUM | Prisma Access Agent: Anti-Tamper Protection Bypass on Windows |
| CVE-2026-0298 | 5.2 MEDIUM | GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP |
| CVE-2026-0296 | 4.5 MEDIUM | GlobalProtect App: Improper Certificate Validation Bypass Vulnerability |
| CVE-2026-0295 | 4.1 MEDIUM | GlobalProtect App: Local Privilege Escalation via Race Condition on macOS |
| CVE-2026-0292 | 2.1 LOW | Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows |
| CVE-2026-0291 | 1.1 LOW | Prisma Access Agent: Authenticated Limited File Deletion on Linux |
| CVE-2026-0289 | 0.5 LOW | Prisma Browser: Inappropriate Implementation in Account Protection |
| CVE-2026-0301 | 0.5 LOW | PAN-OS: Information Disclosure Vulnerability in URL Filtering |
| CVE-2026-0290 | 0.5 LOW | Prisma Browser: Sensitive Information Disclosure Vulnerability |
No comments yet