Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GlobalProtect App — Vulnerabilities & Security Advisories 32

All 32 CVE vulnerabilities found in GlobalProtect App, with AI-generated Chinese analysis, references, and POCs.

This page catalogues Common Weakness Enumerations associated with the GlobalProtect App product developed by Palo Alto Networks. It serves as a centralized resource for security professionals analyzing the specific vulnerability landscape of this network security solution. The content aggregates data regarding known security flaws, configuration errors, and implementation weaknesses that have been identified and documented over time. The vulnerabilities collected on this page primarily include issues related to authentication bypass, buffer overflows, cross-site scripting, and improper access controls within the GlobalProtect application interface and underlying architecture. The data spans from the initial releases of the software up to the present day, ensuring a comprehensive historical view of security regressions and fixes. This extensive timeline allows users to correlate vulnerability emergence with specific product versions and patch releases. Visitors can utilize this resource to track the vendor’s response patterns and advisory release schedules for the GlobalProtect App. It provides the ability to understand the prevalence and nature of specific weakness classes within this particular software environment. Users may also look up the complete vulnerability history of the product to assess long-term security hygiene, identify recurring attack vectors, and evaluate the effectiveness of mitigation strategies over time. This structured approach facilitates deeper threat modeling and informs more robust defense planning for organizations relying on Palo Alto Networks’ secure remote access technologies.

Vendor: Palo Alto Networks

CVE IDTitleCVSSSeverityPublished
CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS CWE-532--2026-06-10
CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities CWE-295--2026-05-13
CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway CWE-787--2026-05-13
CVE-2026-0251 GlobalProtect App: Local Privilege Escalation Vulnerabilities CWE-426--2026-05-13
CVE-2025-2183 GlobalProtect App: Improper Certificate Validation Leads to Privilege Escalation CWE-295 8.0AIHighAI2025-08-13
CVE-2025-2179 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App CWE-266 6.1AIMediumAI2025-07-29
CVE-2025-0141 GlobalProtect App: Privilege Escalation (PE) Vulnerability CWE-426 7.8AIHighAI2025-07-09
CVE-2025-0140 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App CWE-266 7.1AIHighAI2025-07-09
CVE-2025-4227 GlobalProtect App: Interception in Endpoint Traffic Policy Enforcement CWE-319 4.6AIMediumAI2025-06-13
CVE-2025-4232 GlobalProtect: Authenticated Code Injection Through Wildcard on macOS CWE-155 7.8AIHighAI2025-06-12
CVE-2025-0135 GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App CWE-266 7.1AIHighAI2025-05-14
CVE-2025-0120 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-250 7.0AIHighAI2025-04-11
CVE-2025-0118 GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability CWE-618 8.8 -2025-03-12
CVE-2025-0117 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-807 7.8 -2025-03-12
CVE-2024-5921 GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation CWE-295 8.0AIHighAI2024-11-27
CVE-2024-9473 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-250 7.8AIHighAI2024-10-09
CVE-2024-5915 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-732 7.8AIHighAI2024-08-14
CVE-2024-5908 GlobalProtect App: Encrypted Credential Exposure via Log Files CWE-532 5.5AIMediumAI2024-06-12
CVE-2024-2432 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-269 4.5 Medium2024-03-13
CVE-2024-2431 GlobalProtect App: Local User Can Disable GlobalProtect CWE-269 5.5 Medium2024-03-13
CVE-2023-0009 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability CWE-807 7.8 High2023-06-14
CVE-2023-0006 GlobalProtect App: Local File Deletion Vulnerability CWE-367 6.3 Medium2023-04-12
CVE-2022-0021 GlobalProtect App: Information Exposure Vulnerability When Using Connect Before Logon CWE-532 3.3 Low2022-02-10
CVE-2022-0019 GlobalProtect App: Insufficiently Protected Credentials Vulnerability on Linux CWE-522 4.7 Medium2022-02-10
CVE-2022-0018 GlobalProtect App: Information Exposure Vulnerability When Connecting to GlobalProtect Portal With Single Sign-On Enabled CWE-201 6.1 Medium2022-02-10
CVE-2022-0017 GlobalProtect App: Improper Link Resolution Vulnerability Leads to Local Privilege Escalation CWE-59 7.0 High2022-02-10
CVE-2022-0016 GlobalProtect App: Privilege Escalation Vulnerability When Using Connect Before Logon CWE-703 7.4 High2022-02-10
CVE-2021-3057 GlobalProtect App: Buffer Overflow Vulnerability When Connecting to Portal or Gateway CWE-121 8.1 High2021-10-13
CVE-2021-3038 GlobalProtect App: Windows VPN kernel driver denial of service (DoS) CWE-20 5.5 Medium2021-04-20
CVE-2020-2033 GlobalProtect App: Missing certificate validation vulnerability can disclose pre-logon authentication cookie CWE-290 5.3 Medium2020-06-10

All 32 known CVE vulnerabilities affecting GlobalProtect App with full Chinese analysis, references, and POCs where available.