# Palo Alto Networks GlobalProtect vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/palo-alto-networks-globalprotect-vulnerabilities
> Updated: 2026-08-26T10:04:23.000Z. Sources: 5. Developments: 2.

Security researcher Martijn van Ramesdonk disclosed five high-risk vulnerabilities affecting Palo Alto Networks’ GlobalProtect VPN and endpoint agent. These flaws, originally reported in early April 2026, allow local, low-privileged users to escalate privileges to root or NT AUTHORITY\SYSTEM on various operating systems. 

One identified method allows for the recovery of a user’s Active Directory password directly from the endpoint. The disclosure has led to discussions regarding vendor response protocols, as the researcher reported that Palo Alto Networks patched some vulnerabilities without providing credit or notification, excluded others from its bug bounty program, and left one vulnerability unpatched.

## Timeline

### 2026-08-26: Palo Alto Networks and SonicWall disclose critical security vulnerabilities

Critical vulnerabilities have been discovered in Palo Alto Networks’ Expedition tool and SonicWall’s NetExtender Linux client, posing risks of unauthorized root access and data theft.

3 sources. https://clstr.news/cluster/palo-alto-networks-and-sonicwall-disclose-critical-security-vulnerabilities

### 2026-08-25: Palo Alto Networks GlobalProtect faces five high-risk vulnerabilities

Researcher Martijn van Ramesdonk disclosed five high-risk vulnerabilities in Palo Alto Networks’ GlobalProtect VPN, including local privilege escalation and potential Active Directory password recovery.

3 sources. https://clstr.news/cluster/palo-alto-networks-globalprotect-faces-five-high-risk-vulnerabilities

---
Cite as: Palo Alto Networks GlobalProtect vulnerabilities. CLSTR, https://clstr.news/situations/palo-alto-networks-globalprotect-vulnerabilities
