Palo Alto Networks GlobalProtect App Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in the Palo Alto Networks GlobalProtect app. This vulnerability allows a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. The issue arises during the processing of requests and responses exchanged between the Portal and Gateway. Notably, the GlobalProtect app on iOS is not affected.

Impact

Exploitation of this vulnerability could lead to a buffer overflow, allowing for arbitrary code execution with SYSTEM privileges.

Remediation

Users can upgrade to GlobalProtect App version 6.3.3-h9 (6.3.3-999), 6.2.8-h10 (6.2.8-948), or 6.0.13 or later, depending on their current version and operating system. For those using the GlobalProtect UWP App, an upgrade to version 6.3.3-h10 or later is recommended.

Added: May 13, 2026, 7:39 PM
Updated: May 13, 2026, 7:39 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
7.5
exploitability
4.4
remediation
7.7
relevance
8.2
threat
0.0
urgency
5.7
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.