< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Palo Alto Networks GlobalProtect faces five high-risk vulnerabilities

Security researcher Martijn van Ramesdonk has disclosed five high-risk vulnerabilities affecting Palo Alto NetworksGlobalProtect VPN and endpoint agent. The vulnerabilities, originally reported in early April 2026, include flaws that allow a local, low-privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows or to root on macOS and Linux.

Two of these issues were integrated into CVE-2026-0251, which carries a CVSS 3.1 base score of 7.8. Additionally, the researcher identified a method to recover a user’s Active Directory password directly from the endpoint by exploiting privileged components.

The disclosure has sparked debate regarding vendor response protocols. Van Ramesdonk reported that Palo Alto Networks patched two of the vulnerabilities without notifying him or providing credit in the official advisory. Furthermore, two other vulnerabilities were reportedly excluded from the company’s bug bounty program, and a fifth remains unpatched.

Entities

GlobalProtect · Martijn van Ramesdonk · National Vulnerability Database · Palo Alto Networks

Claims

What the coverage asserts, and how many sources carry each claim.