CVE-2026-0296EPSS p0.6%
CVE-2026-0296CVE-2026-0296
Description
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Scoring
| EPSS | 0.09% probability of exploitation · percentile 0.6% · 2026-08-13T12:03:51Z |
| Last modified | 2026-08-13 |