Critical Vulnerabilities in Palo Alto GlobalProtect Expose Enterprises to Privilege Escalation and AD Credential Theft
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities in Palo Alto Networks’ GlobalProtect, a widely used enterprise VPN and endpoint agent for Windows, macOS, and Linux. The flaws include local privilege escalation vulnerabilities that could allow attackers with low-level access to gain SYSTEM privileges on Windows or root access on macOS and Linux.
Two of the vulnerabilities were addressed under CVE-2026-0251, a local privilege escalation flaw with a CVSS score of 7.8. Exploitation requires local access but poses significant risk due to GlobalProtect’s elevated permissions and integration with corporate identity systems. Palo Alto Networks confirmed that successful attacks could enable arbitrary command execution with high-level privileges.
Beyond privilege escalation, van Ramesdonk identified a method to recover Active Directory passwords from affected endpoints by exploiting GlobalProtect’s privileged components. If confirmed, this could allow attackers to steal domain credentials, enabling lateral movement, VPN access, or broader attacks on Active Directory infrastructure.
The disclosure also highlights challenges in the coordinated vulnerability disclosure process. Van Ramesdonk reported the flaws to Palo Alto Networks in April 2026, but stated the vendor patched CVE-2026-0251 without crediting him and deemed two other issues out of scope for its bug bounty program. A fifth vulnerability remains unpatched and undisclosed pending remediation. The researcher described the process as a breakdown in communication, citing missed deadlines and extensive back-and-forth with Palo Alto’s security team.
Proof-of-concept exploits for four of the vulnerabilities are publicly available via van Ramesdonk’s GlobalUnprotect research site, while a fifth remains withheld until a fix is released. Affected versions include GlobalProtect 6.0, 6.2, and 6.3 across all supported platforms. Palo Alto Networks has released patched builds and reported no known exploitation in the wild.
Organizations using GlobalProtect are urged to update to the latest versions, restrict local administrative access, and monitor for suspicious activity, including unusual SYSTEM/root process execution and Active Directory authentication anomalies.
Source: https://gbhackers.com/5-palo-alto-globalprotect-flaws/
Palo Alto Networks cybersecurity rating report: https://www.rankiteo.com/company/palo-alto-networks
"id": "PAL1787639105",
"linkid": "palo-alto-networks",
"type": "Vulnerability",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Technology',
'Cybersecurity',
'VPN Services'],
'location': 'Global',
'name': 'Palo Alto Networks GlobalProtect Customers',
'type': 'Enterprise'}],
'attack_vector': 'Local Access',
'customer_advisories': 'Organizations using GlobalProtect are urged to update '
'to the latest versions and monitor for suspicious '
'activity.',
'data_breach': {'personally_identifiable_information': 'Active Directory '
'credentials',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Active Directory credentials'},
'date_detected': '2026-04',
'description': 'Security researcher Martijn van Ramesdonk disclosed five '
'vulnerabilities in Palo Alto Networks’ GlobalProtect, a '
'widely used enterprise VPN and endpoint agent for Windows, '
'macOS, and Linux. The flaws include local privilege '
'escalation vulnerabilities that could allow attackers with '
'low-level access to gain SYSTEM privileges on Windows or root '
'access on macOS and Linux. Additionally, a method to recover '
'Active Directory passwords from affected endpoints was '
'identified, enabling potential lateral movement and broader '
'attacks on Active Directory infrastructure.',
'impact': {'data_compromised': 'Active Directory credentials',
'identity_theft_risk': 'High (due to AD credential theft)',
'operational_impact': 'Potential lateral movement and broader '
'attacks on Active Directory infrastructure',
'systems_affected': ['Windows', 'macOS', 'Linux']},
'investigation_status': 'Ongoing (one vulnerability remains unpatched)',
'lessons_learned': 'Challenges in coordinated vulnerability disclosure '
'processes, importance of timely patching and monitoring '
'for privilege escalation and credential theft risks.',
'post_incident_analysis': {'corrective_actions': 'Patching vulnerabilities, '
'restricting local '
'administrative access, '
'enhancing monitoring for '
'privilege escalation and '
'credential theft',
'root_causes': 'Vulnerabilities in GlobalProtect’s '
'privileged components and '
'integration with corporate '
'identity systems'},
'recommendations': 'Update to the latest versions of GlobalProtect, restrict '
'local administrative access, monitor for suspicious '
'activity including unusual SYSTEM/root process execution '
'and Active Directory authentication anomalies.',
'references': [{'source': 'Martijn van Ramesdonk’s GlobalUnprotect research '
'site'}],
'response': {'containment_measures': 'Update to the latest patched versions '
'of GlobalProtect',
'enhanced_monitoring': 'Monitor for unusual SYSTEM/root process '
'execution and Active Directory '
'authentication anomalies',
'remediation_measures': 'Restrict local administrative access, '
'monitor for suspicious activity'},
'title': 'Critical Vulnerabilities in Palo Alto GlobalProtect Expose '
'Enterprises to Privilege Escalation and AD Credential Theft',
'type': ['Privilege Escalation', 'Credential Theft'],
'vulnerability_exploited': ['CVE-2026-0251',
'Unpatched vulnerabilities in GlobalProtect']}