Five High-Risk Vulnerabilities Found in Palo Alto GlobalProtect VPN
A security researcher has publicly disclosed five vulnerabilities in Palo Alto Networks’ GlobalProtect, the VPN and endpoint agent deployed across thousands of enterprise networks worldwide. Two are now tracked as CVE-2026-0251, confirmed local privilege escalation flaws carrying a CVSS score of 7.8. Four proof-of-concept exploits are already publicly available, raising the risk for any network that has not yet patched.
The researcher, Martijn van Ramesdonk, submitted the findings to Palo Alto Networks in early April 2026. He published his disclosure on 25 August 2026 after what he describes as months of missed deadlines, unreturned credit, and a disclosure process he believes is fundamentally broken.
CVE-2026-0251: How These GlobalProtect Flaws Escalate a Local User to Full System Administrator
The two patched vulnerabilities behind CVE-2026-0251 are local privilege escalation (LPE) flaws. LPE means an attacker who already has basic, low-level access to a machine can elevate themselves to complete control of the system.
On Windows, exploitation elevates the attacker to NT AUTHORITY\SYSTEM, the highest-privileged built-in account in the Windows operating system. On macOS and Linux, the attacker gains root access. From either position, the attacker can execute any command, access any file, and install any software without restriction.
The research disclosure
confirmed the National Vulnerability Database assigned this a CVSS 3.1 base score of 7.8, placing it firmly in the High severity category.
The Finding That Could Unlock an Entire Corporate Network: Active Directory Password Recovery
Beyond the LPE flaws, van Ramesdonk also discovered a method to recover a user’s Active Directory password directly from the endpoint by abusing privileged GlobalProtect components.
Active Directory is the identity system that most corporate networks use to control who can log in, what systems they can reach, and what data they can access. Recovering a credential from it does not just compromise one machine. It can let an attacker move laterally across the entire corporate network using a valid, trusted account.
This finding sits outside the patched CVE-2026-0251 and its remediation status has not been publicly confirmed by Palo Alto Networks.
Every Enterprise on GlobalProtect 6.0, 6.2, or 6.3 Across Windows, macOS, and Linux Is Exposed
The vulnerabilities affect multiple branches of GlobalProtect 6.0, 6.2, and 6.3 across all three major platforms. Palo Alto Networks has published patched builds for these branches.
GlobalProtect runs with elevated privileges by design and sits inside corporate identity infrastructure. That trusted position makes LPE and credential-recovery flaws in this product significantly more dangerous than similar bugs in standard user applications.
Palo Alto Networks stated it is not currently aware of active exploitation in the wild.
Four Working Exploits Are Already Public While One Flaw Still Has No Fix
Four of the five vulnerabilities now have publicly available proof-of-concept (PoC) exploits. A PoC is working code that shows precisely how to reproduce an attack. Once a PoC is public, other threat actors can adapt it for their own campaigns with far less effort.
The fifth vulnerability remains unpatched. Van Ramesdonk is withholding its PoC until Palo Alto releases an official fix, but no timeline for that fix has been announced.
Patched Without Credit and Two Bugs Rejected From the Bounty Program: The Researcher’s Account
Van Ramesdonk says Palo Alto Networks patched the two CVE-2026-0251 vulnerabilities without notifying him and without crediting him in the advisory.
Two additional vulnerabilities were reportedly declared out of scope for Palo Alto’s bug bounty program. The researcher described exchanging more than 40 emails with Palo Alto’s Product Security Incident Response Team (PSIRT) over several months, with multiple missed and shifting disclosure deadlines.
He framed the experience as evidence of a structural problem. As AI tools speed up how quickly researchers find vulnerabilities, the internal vendor processes for validating, patching, and acknowledging those findings are struggling to keep pace.
How to Protect Your Organisation From the GlobalProtect Flaws Right Now
If your organisation uses Palo Alto GlobalProtect, take these steps today:
Check which GlobalProtect version is installed on your endpoints and confirm whether it falls within the 6.0, 6.2, or 6.3 branches.
Apply Palo Alto’s patched builds for CVE-2026-0251 immediately. The fixes are available. Check Palo Alto’s official security advisory for the specific build numbers.
Prioritise internet-facing and identity-adjacent deployments for immediate patching, given that four working exploits are now publicly available.
Review endpoint logs for unusual privilege escalation activity or unexpected processes on GlobalProtect machines going back to April 2026.
Monitor your Active Directory for unusual login attempts or lateral movement that could indicate credential recovery and reuse.
One Flaw Still Without a Fix and a Disclosure Debate That Is Far From Over
The fifth vulnerability has no patch and no confirmed remediation timeline. Security teams should treat the current patches as partial, not full, resolution of the GlobalProtect risk.
This case has also reignited a wider debate about vendor accountability in coordinated vulnerability disclosure. As the pace of vulnerability discovery accelerates, pressure on PSIRT teams to respond faster, communicate clearly, and credit researchers properly will only grow. Further updates on the fifth flaw are expected as Palo Alto’s remediation work continues.
No Comment! Be the first one.