What is CVE-2026-0297?
This is a buffer overflow vulnerability in the Palo Alto Networks GlobalProtect™ app. A man-in-the-middle attacker or rogue gateway can exploit it to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM on Windows, root on macOS/Linux). Updating the app to the latest version is recommended.
Azərbaycanca: Bu, Palo Alto Networks GlobalProtect™ tətbiqində tapılan buffer overflow zəifliyidir. Man-in-the-middle hücumçusu və ya saxta şlüz bu zəiflikdən istifadə edərək sistem proseslərini poza və yüksək imtiyazlarla (Windows-da SYSTEM, macOS/Linux-da root) ixtiyari kod icra edə bilər. Tətbiqi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which versions of the Palo Alto Networks GlobalProtect™ app are affected by CVE-2026-0297?
The provided information does not specify the affected versions. It is only recommended to update the app to the latest version.
What can an attacker gain by successfully exploiting CVE-2026-0297?
A man-in-the-middle attacker or rogue gateway can exploit this buffer overflow vulnerability to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM on Windows, root on macOS/Linux).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.