Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GlobalProtect App — Vulnerabilities & Security Advisories 38

All 38 CVE vulnerabilities found in GlobalProtect App, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the Palo Alto Networks GlobalProtect App. It compiles a chronological record of disclosed security flaws specific to this product, covering advisories published from the initial release through the most recent updates. The collection focuses on weakness types such as memory corruption, authentication bypass, and configuration errors that have been formally identified by the vendor or third-party researchers. By examining this aggregated data, you can track how the vendor has responded to reported issues over time. This resource allows you to understand the evolution of the GlobalProtect App's security posture, identify recurring weakness classes, and review the product's complete vulnerability history. The entries are organized to highlight the severity and impact of each defect, providing a structured view of the risks that have required patches or workarounds. Use this index to map out the timeline of disclosures and assess which vulnerability categories have been most frequent. The data supports both technical analysis and broader risk assessment for environments relying on the GlobalProtect App for secure remote access. This is not a marketing overview but a factual inventory of past security events. The time range extends from the earliest public advisory for the product to the latest released fix, ensuring a comprehensive historical perspective on the application's security lifecycle.

Vendor: Palo Alto Networks

CVE ID Title CVSS Severity Published
CVE-2026-0307 GlobalProtect App: Local Privilege Escalation Vulnerabilities CWE-426 5.9 Medium 2026-09-10
CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities CWE-426 5.9 Medium 2026-08-13
CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) CWE-94 5.2 Medium 2026-08-13
CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake CWE-787 5.2 Medium 2026-08-13
CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability CWE-295 4.5 Medium 2026-08-13
CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS CWE-362 4.1 Medium 2026-08-13
CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS CWE-532 - - 2026-06-10
CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities CWE-295 - - 2026-05-13
CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway CWE-787 - - 2026-05-13
CVE-2026-0251 GlobalProtect App: Local Privilege Escalation Vulnerabilities CWE-426 - - 2026-05-13
CVE-2025-2183 GlobalProtect App: Improper Certificate Validation Leads to Privilege Escalation CWE-295 8.0AI High AI 2025-08-13
CVE-2025-2179 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App CWE-266 6.1AI Medium AI 2025-07-29
CVE-2025-0141 GlobalProtect App: Privilege Escalation (PE) Vulnerability CWE-426 7.8AI High AI 2025-07-09
CVE-2025-0140 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App CWE-266 7.1AI High AI 2025-07-09
CVE-2025-4227 GlobalProtect App: Interception in Endpoint Traffic Policy Enforcement CWE-319 4.6AI Medium AI 2025-06-13
CVE-2025-4232 GlobalProtect: Authenticated Code Injection Through Wildcard on macOS CWE-155 7.8AI High AI 2025-06-12
CVE-2025-0135 GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App CWE-266 7.1AI High AI 2025-05-14
CVE-2025-0120 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-250 7.0AI High AI 2025-04-11
CVE-2025-0118 GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability CWE-618 8.8 - 2025-03-12
CVE-2025-0117 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-807 7.8 - 2025-03-12
CVE-2024-5921 GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation CWE-295 8.0AI High AI 2024-11-27
CVE-2024-9473 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-250 7.8AI High AI 2024-10-09
CVE-2024-5915 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-732 7.8AI High AI 2024-08-14
CVE-2024-5908 GlobalProtect App: Encrypted Credential Exposure via Log Files CWE-532 5.5AI Medium AI 2024-06-12
CVE-2024-2432 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-269 4.5 Medium 2024-03-13
CVE-2024-2431 GlobalProtect App: Local User Can Disable GlobalProtect CWE-269 5.5 Medium 2024-03-13
CVE-2023-0009 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-807 7.8 High 2023-06-14
CVE-2023-0006 GlobalProtect App: Local File Deletion Vulnerability CWE-367 6.3 Medium 2023-04-12
CVE-2022-0021 GlobalProtect App: Information Exposure Vulnerability When Using Connect Before Logon CWE-532 3.3 Low 2022-02-10
CVE-2022-0019 GlobalProtect App: Insufficiently Protected Credentials Vulnerability on Linux CWE-522 4.7 Medium 2022-02-10

All 38 known CVE vulnerabilities affecting GlobalProtect App with full Chinese analysis, references, and POCs where available.