LATEST View all updates

GlobalProtect CVE-2026-0307: Affected Versions and Full Fix Path

Check affected GlobalProtect versions, available fixes, and why PAN-OS or Prisma Access also needs remediation.

Enterprise remote-access security illustration showing endpoint and backend remediation for CVE-2026-0307

Signal Brief

  • CVE-2026-0307 affects specified GlobalProtect versions on Windows, macOS and Linux; Palo Alto Networks says iOS, Android and ChromeOS are not affected.
  • A local low-privileged user may be able to escalate to SYSTEM on Windows or root on macOS and Linux.
  • Full remediation requires both the affected GlobalProtect client and the applicable PAN-OS or Prisma Access backend to reach fixed versions.
  • Some client fixes are available now, while others remain scheduled for September 17, September 28 or October 29, 2026.

GlobalProtect CVE-2026-0307 affects specified Palo Alto Networks GlobalProtect versions on Windows, macOS and Linux. Palo Alto Networks says a local low-privileged user on an affected endpoint could escalate privileges to NT AUTHORITYSYSTEM on Windows or root on macOS and Linux, allowing commands to run with administrative privileges.

The remediation has an important two-part requirement: administrators should not treat a GlobalProtect client update alone as complete. Palo Alto Networks says both the affected GlobalProtect app and the applicable PAN-OS or Prisma Access environment must reach fixed versions. Some client fixes are already available, while other platform builds remain scheduled for September 17, September 28 or October 29, 2026.

Which platforms are affected by GlobalProtect CVE-2026-0307?

Palo Alto Networks identifies affected GlobalProtect versions on Windows, macOS and Linux. The vendor says iOS, Android and ChromeOS are not affected by this CVE.

The published attack vector is local rather than remote. The issue requires a local user with low privileges on an affected endpoint; Palo Alto Networks does not describe CVE-2026-0307 as an unauthenticated internet-exploitable vulnerability.

What can CVE-2026-0307 allow?

On a vulnerable system, a local low-privileged user may be able to execute arbitrary commands with elevated rights. Palo Alto Networks describes the resulting privilege as SYSTEM on Windows and root on macOS or Linux.

This makes the vulnerability relevant to enterprise endpoint security even though the attacker already needs local low-privilege access. The risk is privilege escalation from a restricted local account to administrative control.

Which GlobalProtect fixes are available now?

The answer depends on the GlobalProtect branch and operating system. Palo Alto Networks identifies fixed target releases including 6.2.8-h14, 6.3.3-h15 and 6.0.15, but availability is staged by platform.

GlobalProtect 6.2 on macOS and Windows

Palo Alto Networks identifies 6.2.8-h14 as the corrected path for affected 6.2 installations on these platforms.

GlobalProtect 6.3 on Linux

The vendor currently expects 6.3.3-h15 on September 17, 2026. Treat this as a scheduled release until it is actually available.

GlobalProtect 6.3 on macOS and Windows

The current vendor schedule places 6.3.3-h15 availability on September 28, 2026.

GlobalProtect 6.0

Palo Alto Networks currently schedules 6.0.15 for Linux and macOS on September 28 and for Windows on October 29, 2026.

Administrators should verify the current Palo Alto Networks matrix before upgrading because a fixed version number in the advisory does not automatically mean that build is already downloadable for every operating system.

Is updating the GlobalProtect client enough?

No. Palo Alto Networks explicitly says full remediation requires upgrading both the GlobalProtect app and the applicable PAN-OS software or Prisma Access environment.

An endpoint can therefore be on a corrected client version while the overall environment still requires backend remediation. The reverse is also true: upgrading PAN-OS or Prisma Access does not by itself prove that affected endpoint clients have reached their fixed versions.

What should PAN-OS administrators check?

Palo Alto Networks provides branch-specific fixed PAN-OS releases in the CVE-2026-0307 advisory. Administrators should compare their exact PAN-OS branch and build against the current vendor matrix rather than assuming one universal PAN-OS version fixes every deployment.

The safest verification state is therefore two-sided: confirm the endpoint GlobalProtect build for that operating system, then confirm the connected PAN-OS environment is also on a vendor-defined fixed release.

What should Prisma Access customers check?

Palo Alto Networks says Prisma Access customers also need the relevant fixed backend version. The vendor indicates that upgrades can be delivered through scheduled maintenance or an on-demand upgrade window, depending on the customer’s service state.

A Prisma Access customer should therefore verify both the endpoint client version and the current Prisma Access backend remediation state before considering CVE-2026-0307 fully addressed.

How do I know whether my environment is fully remediated?

Check the endpoint operating system

Confirm whether the endpoint runs Windows, macOS or Linux. iOS, Android and ChromeOS are not affected by this CVE according to Palo Alto Networks.

Check the GlobalProtect branch and build

Compare the installed client against the vendor’s current affected and fixed-version matrix for that operating system.

Check whether the fixed client build has shipped

Do not treat a future ETA as an available patch. Several fixes remain scheduled for September or October.

Check PAN-OS or Prisma Access

Verify the backend is also on a vendor-defined fixed version. Client-only remediation is not sufficient.

Recheck after staged release dates

Review the vendor advisory again when scheduled client builds are due because availability dates or versions can change.

Is there a workaround?

Palo Alto Networks says there is no known workaround for CVE-2026-0307. Where the fixed client release for a particular operating system or branch is still pending, administrators should track the vendor’s staged release schedule and current backend remediation guidance rather than inventing an unsupported configuration workaround.

Is CVE-2026-0307 actively exploited?

Palo Alto Networks currently says it is not aware of malicious exploitation of CVE-2026-0307. That is a current evidence state, not a permanent guarantee. TPS is not describing this vulnerability as actively exploited or as a confirmed CISA Known Exploited Vulnerabilities entry on the evidence reviewed.

What happens next?

The next scheduled material checkpoint is September 17, 2026, when Palo Alto Networks currently expects GlobalProtect 6.3.3-h15 for Linux. Additional client milestones are scheduled for September 28 and October 29.

This same article should be updated if those builds ship, if Palo Alto Networks changes the release schedule, if exploitation is confirmed, if a workaround appears, if CISA adds the CVE to KEV, or if the PAN-OS or Prisma Access remediation matrix changes.

Verification note: TPS reviewed Palo Alto Networks’ CVE-2026-0307 advisory and current CNA/CVE remediation information, including platform impact, staged client-fix availability, backend remediation requirements, workaround status and the vendor’s current exploitation statement. Future-dated client releases remain expected rather than completed until Palo Alto Networks makes them available.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance on GlobalProtect CVE-2026-0307. Palo Alto Networks confirms the vulnerability and remediation model, but several client fixes are still scheduled rather than released, and exploitation status can change. Verify the current Palo Alto Networks advisory and your exact client, PAN-OS or Prisma Access versions before consequential security action.