Five GlobalProtect Vulnerabilities Expose Enterprise VPN Users to Privilege Escalation
ID: 6e26f423-b965-5e70-b504-f84034b20124
STIX ID: report--6e26f423-b965-5e70-b504-f84034b20124
Feed Name: Cyber Press
A researcher disclosed five vulnerabilities in Palo Alto Networks GlobalProtect, including local privilege-escalation flaws (CVE-2026-0251, CVSS 7.8) that can grant SYSTEM/root and an alleged method to recover Active Directory passwords from affected endpoints; several proof-of-concept exploits are public, Palo Alto has released patches for multiple versions and platforms while one issue remains unpatched, and the vendor reports no confirmed exploitation in the wild—customers are advised to identify affected versions, apply fixes, and limit local access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
