Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-0297

CVE-2026-0297: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

1 advisory
  • Advisory severityHigh7.7

    High [CVE-2026-0297] GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

    CVE-2026-0297Source published

    CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

    Affected products in this advisory
    • GlobalProtect App
    Source-reported affected versions
    • GlobalProtect App 6.3: < 6.3.3-h15 on Linux< 6.3.3-h14 on macOS< 6.3.3-h14 on Windows< 6.3.5 on iOS< 6.3.5 on Android< 6.3.5 on Chrome OS
    • GlobalProtect App 6.2: All on Linux< 6.2.8-h13 on macOS< 6.2.8-h13 on Windows
    • GlobalProtect App 6.0: < 6.0.15 on Linux< 6.0.15 on macOS< 6.0.15 on Windows< 6.0.15 on iOS< 6.0.15 on Android< 6.0.15 on Chrome OS
    Source-reported fixed versions
    • GlobalProtect App >= 6.3.3-h15
    • GlobalProtect App >= 6.0.15
    • GlobalProtect App >= 6.3.3-h14
    • GlobalProtect App >= 6.2.8-h13

    1 more entries in the full advisory.

    Mitigation guidance
    • VersionMinor VersionSuggested Solution GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later.
    Workarounds
    • Customers can mitigate the risk of this issue by taking either of the following three actions:
    • Enforce SSL-Only VPN Connections: Modify your GlobalProtect Portal configurations to disable IPSec/UDP tunneling, forcing the client applications to connect exclusively via SSL VPN mode.
    • Therefore the first connection is not protected.

Android app · Google Play

Monitor future Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery