< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 5 sources · 2 days · First seen · Last updated

Palo Alto Networks GlobalProtect vulnerabilities

Overview

Security researcher Martijn van Ramesdonk disclosed five high-risk vulnerabilities affecting Palo Alto Networks’ GlobalProtect VPN and endpoint agent. These flaws, originally reported in early April 2026, allow local, low-privileged users to escalate privileges to root or NT AUTHORITY\SYSTEM on various operating systems.

One identified method allows for the recovery of a user’s Active Directory password directly from the endpoint. The disclosure has led to discussions regarding vendor response protocols, as the researcher reported that Palo Alto Networks patched some vulnerabilities without providing credit or notification, excluded others from its bug bounty program, and left one vulnerability unpatched.

Entities

Palo Alto Networks · GlobalProtect · Expedition · National Vulnerability Database · SonicWall

Timeline

  1. 18 days ago

    [TECHNOLOGY] 3 sources
    Palo Alto Networks and SonicWall disclose critical security vulnerabilities

    Critical vulnerabilities have been discovered in Palo Alto Networks’ Expedition tool and SonicWall’s NetExtender Linux client, posing risks of unauthorized root access and data theft.

  2. 19 days ago

    [TECHNOLOGY] 3 sources
    Palo Alto Networks GlobalProtect faces five high-risk vulnerabilities

    Researcher Martijn van Ramesdonk disclosed five high-risk vulnerabilities in Palo Alto Networks’ GlobalProtect VPN, including local privilege escalation and potential Active Directory password recovery.

Sources

blog.vpntracker.com · cybernoz.com · cybersecuritynews.com · invitehealth.substack.com · istio.io