Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 5 sources · 2 days · First seen · Last updated
Palo Alto Networks GlobalProtect vulnerabilities
Overview
Security researcher Martijn van Ramesdonk disclosed five high-risk vulnerabilities affecting Palo Alto Networks’ GlobalProtect VPN and endpoint agent. These flaws, originally reported in early April 2026, allow local, low-privileged users to escalate privileges to root or NT AUTHORITY\SYSTEM on various operating systems.
One identified method allows for the recovery of a user’s Active Directory password directly from the endpoint. The disclosure has led to discussions regarding vendor response protocols, as the researcher reported that Palo Alto Networks patched some vulnerabilities without providing credit or notification, excluded others from its bug bounty program, and left one vulnerability unpatched.
Entities
Palo Alto Networks · GlobalProtect · Expedition · National Vulnerability Database · SonicWall
Timeline
-
18 days ago
[TECHNOLOGY] 3 sourcesPalo Alto Networks and SonicWall disclose critical security vulnerabilitiesCritical vulnerabilities have been discovered in Palo Alto Networks’ Expedition tool and SonicWall’s NetExtender Linux client, posing risks of unauthorized root access and data theft.
-
19 days ago
[TECHNOLOGY] 3 sourcesPalo Alto Networks GlobalProtect faces five high-risk vulnerabilitiesResearcher Martijn van Ramesdonk disclosed five high-risk vulnerabilities in Palo Alto Networks’ GlobalProtect VPN, including local privilege escalation and potential Active Directory password recovery.
Sources
blog.vpntracker.com · cybernoz.com · cybersecuritynews.com · invitehealth.substack.com · istio.io