CVE-2026-0251Disclosure(paloaltonetworks / globalprotect)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch paloaltonetworks globalprotect systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • globalprotect

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked 7d ago at 2 mentions (2026-05-13); latest day: 1
  • 9 total mentions across 8 days

Affected systems

Products
globalprotect

2 versions affected across 1 product

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-05-13: 2Mentions · 2026-05-14: 1Mentions · 2026-05-16: 1Mentions · 2026-08-23: 1Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Mentions · 2026-08-30: 1Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-08-27: 1PoC Mentioned / Linked · 2026-09-02: 1Exploit Tool / Code · 2026-08-23: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 1Technical Details · 2026-05-16: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-02: 105-1305-1405-1608-2308-2708-2808-3009-02
Signal classification3 categories
Disclosure
666.7%
Patch
222.2%
Exploit
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-132
Disclosure2
2026-05-141
Disclosure1
2026-05-161
Disclosure1
2026-08-231
Exploit1
2026-08-271
Disclosure1
2026-08-281
Patch1
2026-08-301
Disclosure1
2026-09-021
Patch1
Full discourse9 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-0251 Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM … https://www.cve.org/CVERecord?id=CVE-2026-0251

    Post summary

    The text announces newly discovered multiple local privilege escalation vulnerabilities (CVE-2026-0251) in Palo Alto Networks GlobalProtect, highlighting that a local user could gain SYSTEM-level access.

    00020341
    57.8K followersView on X
  • Cyber Edition@CyberEdition
    Disclosure

    🔓 Five high-risk flaws were found in Palo Alto GlobalProtect. CVE-2026-0251 can let local users gain SYSTEM/root access, while 4 PoCs are already public. One flaw remains unpatched. Organizations should update GlobalProtect now. #CyberSecurity #VPN Read more: https://thecyberedition.com/palo-alto-globalprotect-vulnerabilities-cve-2026-0251/

    Post summary

    Five critical flaws were disclosed for Palo Alto GlobalProtect, including CVE‑2026‑0251 that permits local privilege escalation. The article highlights the availability of PoCs, urges immediate patching, and indicates one flaw remains unpatched.

    00010142
    767 followersView on X
  • Zer0@zer0cool12342
    Exploit

    4 working exploits for Palo Alto GlobalProtect VPN are now public! - 2x SYSTEM privilege escalation for <6.3.3-h11 & < 6.2.8-h10 x86/x64 - DLL Sideloading - Code Exec COM Hijack Full PoC code + writeups on CVE-2026-0251 & more: http://globalunprotect.io & http://github.com/G-Unprotect/Exploits https://t.co/lDPMN1CLUv

    Post summary

    The post announces that four working exploit modules for Palo Alto GlobalProtect VPN (including CVE-2026-0251) are publicly available, complete with PoC code and detailed technical specifics.

    00010102
    153 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Palo Alto GlobalProtect の脆弱性である CVE-2026-0251 などが FIX:ローカル権限昇格の恐れ https://iototsecnews.jp/2026/08/25/researcher-discloses-five-high-risk-vulnerabilities-in-palo-alto-globalprotect-vpn/ Palo Alto Networks の GlobalProtect における脆弱性 CVE-2026-0251 などについて解説する記事です。多くの企業で導入されている VPN 環境において、システム内部への侵入を攻撃者に許し、深刻な権限奪取や認証情報の漏洩に至る問題が生じています。影響として端末上での最高権限獲得/Active Directory パスワードの外部流出/不正コマンドの実行/PoC による攻撃の容易化などが挙げられます。 対応策は修正版ビルドへの適用/セキュリティパッチの最新化/認証情報の変更/構成の見直しなどが推奨されます。 #CVE20260251 #GlobalProtect #PaloAlto #Vulnerability

    Post summary

    CVE‑2026‑0251 in Palo Alto GlobalProtect enables local privilege escalation and credential exfiltration; patches and configuration updates are recommended to mitigate the risk.

    00000161
    510 followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Disclosure

    برای یکی از اجرای فایروال Paolo alto یعنی GlobalProtect، آسیب پذیری با کد شناسایی CVE-2026-0251 از نوع privilege escalation منتشر شده که به هکرها امکان افزایش سطح دسترسی به یوزر system در ویندوز و Root در لینوکس و بدست آوردن پسورد یوزر در Active Directory را نیز می دهد. https://t.co/7YMeNxprTD

    Post summary

    The post announces CVE-2026-0251, a privilege‑escalation bug in Palo Alto GlobalProtect that lets attackers raise privileges to system/root and grab AD passwords; no PoC, exploit, or patch details are provided.

    0000077
    208 followersView on X
  • Vistem Solutions@VistemSolutions
    Patch

    CVE-2026-0251: GlobalProtect Privilege Escalation Flaw CVE-2026-0251 affects the Palo Alto GlobalProtect app and may allow local privilege escalation. Review impacted versions, apply vendor guidance, and patch quickly to reduce risk. Need help securing your environment? Contact Vistem Solutions: sales@vistem.com #Cybersecurity #VulnerabilityManagement #SecureFuture #VistemSolutions https://www.sentinelone.com/vulnerability-database/cve-2026-0251/?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    CVE‑2026‑0251 is a local privilege escalation flaw affecting Palo Alto GlobalProtect. The notice stresses reviewing impacted versions and applying vendor patches promptly.

    0000039
    87 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-0251 | Palo Alto GlobalProtect App/Global Protect App on Windows untrusted search path (EUVD-2026-30102 / WID-SEC-2026-1542) https://ift.tt/sujQ1Ko A vulnerability has been found in Palo Alto GlobalProtect App and Global Protect App on Windows and classified as proble…

    Post summary

    CVE‑2026‑0251 is an untrusted search path vulnerability disclosed for Palo Alto GlobalProtect App on Windows; no PoC, exploit, active use, or patch details are provided.

    0000078
    974 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0251 Local Privilege Escalation in Palo Alto Networks GlobalProtect App on Windows, macOS, and Linux https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0251

    Post summary

    A local privilege escalation vulnerability (CVE‑2026‑0251) in Palo Alto Networks GlobalProtect across Windows, macOS, and Linux has been disclosed with basic technical details, but no evidence of exploitation, PoC, patch, or false‑positive claims.

    0000070
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-0251 Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM … https://www.cve.org/CVERecord?id=CVE-2026-0251 ----- Traducción: CVE-2026-0251 Mú… http://infoflow.cloud`

    Post summary

    The tweet announces the CVE‑2026‑0251 local privilege escalation in Palo Alto Networks GlobalProtect, providing a link to the CVE record and brief technical details.

    0000061
    77 followersView on X
CPE platform detail28 entries

28 of 28 entries

PartVendorProductVersionTarget SWTarget HW
Apppaloaltonetworksglobalprotect-linux-
Apppaloaltonetworksglobalprotect-macos-
Apppaloaltonetworksglobalprotect-windows-
Apppaloaltonetworksglobalprotect6.2.8macos-
Apppaloaltonetworksglobalprotect6.2.8windows-
Apppaloaltonetworksglobalprotect6.2.8macos-
Apppaloaltonetworksglobalprotect6.2.8macos-
Apppaloaltonetworksglobalprotect6.2.8windows-
Apppaloaltonetworksglobalprotect6.3.3linux-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3linux-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-
Apppaloaltonetworksglobalprotect6.3.3macos-
Apppaloaltonetworksglobalprotect6.3.3windows-

Explore more