CVE-2026-0295

HIGHCVSS 7.00% EPSS

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

Published 2026-08-13 · last modified 2026-09-10

Affected products

VendorProduct
paloaltonetworksglobalprotect

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.