started · updated
Palo Alto Networks GlobalProtect faces five high-risk vulnerabilities
Security researcher Martijn van Ramesdonk has disclosed five high-risk vulnerabilities affecting Palo Alto Networks’ GlobalProtect VPN and endpoint agent. The vulnerabilities, originally reported in early April 2026, include flaws that allow a local, low-privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows or to root on macOS and Linux.
Two of these issues were integrated into CVE-2026-0251, which carries a CVSS 3.1 base score of 7.8. Additionally, the researcher identified a method to recover a user’s Active Directory password directly from the endpoint by exploiting privileged components.
The disclosure has sparked debate regarding vendor response protocols. Van Ramesdonk reported that Palo Alto Networks patched two of the vulnerabilities without notifying him or providing credit in the official advisory. Furthermore, two other vulnerabilities were reportedly excluded from the company’s bug bounty program, and a fifth remains unpatched.
Entities
GlobalProtect · Martijn van Ramesdonk · National Vulnerability Database · Palo Alto Networks
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] A fifth vulnerability remains unpatched and undisclosed while remediation work continues. cybersecuritynews.com · cybernoz.com
- [● 2 SOURCES] Researcher Martijn van Ramesdonk disclosed five high-risk vulnerabilities in Palo Alto Networks GlobalProtect. cybersecuritynews.com · cybernoz.com
- [● 2 SOURCES] A method was discovered to recover a user’s Active Directory password directly from the endpoint. cybersecuritynews.com · cybernoz.com
- [● 2 SOURCES] Two vulnerabilities were folded into CVE-2026-0251, which allow local privilege escalation on Windows, macOS, and Linux. cybersecuritynews.com · cybernoz.com
- [● 2 SOURCES] The CVE-2026-0251 flaws have a CVSS 3.1 base score of 7.8. cybersecuritynews.com · cybernoz.com
- [● 2 SOURCES] Palo Alto Networks patched two vulnerabilities without notifying the researcher or providing credit in the advisory. cybersecuritynews.com · cybernoz.com
- [● 2 SOURCES] Two vulnerabilities were deemed out of scope for the vendor’s bug bounty program. cybersecuritynews.com · cybernoz.com