Skip to content
VulniPulse
High7.7Vendor: MediumPalo Alto Networks Updated

High [CVE-2026-0298] GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

This high-severity Palo Alto Networks advisory covers CVE-2026-0298 affecting GlobalProtect App.

CVE-2026-0298 Published Aug 12, 2026
Affected products & platforms
Palo Alto NetworksGlobalProtect
Open vendor advisory

Android app · Google Play

Monitor future Palo Alto Networks CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

Affected versions
  • GlobalProtect App 6.3: < 6.3.3-h14 (6.3.3-1121) on Windows
  • GlobalProtect App 6.2: < 6.2.8-h13 (6.2.8-1045) on Windows
  • GlobalProtect App 6.0: < 6.0.15 on Windows (ETA: 08/31)

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions
  • GlobalProtect App >= 6.3.3-h14
  • GlobalProtect App >= 6.2.8-h13
  • GlobalProtect App >= 6.0.15

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • VersionMinor VersionSuggested Solution GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later.
  • GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later.
  • GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later.
  • GlobalProtect App All on macOSNo action needed.GlobalProtect App All on LinuxNo action needed.GlobalProtect App All on iOSNo action needed.GlobalProtect App All on AndroidNo action needed.GlobalProtect App All on Chrome OSNo action needed.
Temporary workarounds
  • Customers can mitigate the risk of this issue by taking either of the following actions:
  • Use Connect Before Logon (CBL) without SAML AuthenticationUse Pre-logon with machine certificate instead of Connect Before Logon (CBL).

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.