AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-0296

MEDIUM · CVSS 4.5 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Improper certificate validation in the Palo Alto Networks GlobalProtect app allows unauthenticated attackers with man-in-the-middle access to intercept and modify communications for affected products on Android and Chrome OS. While VPN tunnel traffic remains secure, this vulnerability could lead to unauthorized data manipulation, making it critical for organizations using these platforms to prioritize patching. Users of the GlobalProtect app on iOS, Android, and Chrome should assess their exposure and implement necessary security measures.

CVE
CVE-2026-0296
Severity
MEDIUM
CVSS
4.5
EPSS
0.09%
Palo Alto Android Chrome

Original NVD Description

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtectâ„¢ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.