CVE-2026-0250
Estado: AnalizadaMedia (5.2)—
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway.
The GlobalProtect app on iOS is not affected.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
- Puntuación base: 5.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-787
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-0250",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-0250",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-13T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "USER",
"baseScore": 5.2,
"Automatable": "NO",
"attackVector": "ADJACENT",
"baseSeverity": "MEDIUM",
"valueDensity": "DIFFUSE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber",
"exploitMaturity": "UNREPORTED",
"providerUrgency": "AMBER",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "psirt@paloaltonetworks.com",
"affectedData": [
{
"vendor": "Palo Alto Networks",
"product": "GlobalProtect App",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "6.3.3-h9 (6.3.3-999)",
"status": "unaffected"
}
],
"version": "6.3.0",
"lessThan": "6.3.3-h9 (6.3.3-999)",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "6.2.8-h10 (6.2.8-948)",
"status": "unaffected"
}
],
"version": "6.2.0",
"lessThan": "6.2.8-h10 (6.2.8-948)",
"versionType": "custom"
}
],
"platforms": [
"Windows",
"MacOS"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "GlobalProtect App",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "6.1.13",
"status": "unaffected"
}
],
"version": "6.1",
"lessThan": "6.1.13",
"versionType": "custom"
}
],
"platforms": [
"Android",
"Chrome OS"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "GlobalProtect App",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "6.3.3-h2 (6.3.3-42)",
"status": "unaffected"
}
],
"version": "6.3.0",
"lessThan": "6.3.3-h2 (6.3.3-42)",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "6.0.11",
"status": "unaffected"
}
],
"version": "6.0.0",
"lessThan": "6.0.11",
"versionType": "custom"
}
],
"platforms": [
"Linux"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "GlobalProtect App",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "6.0.13",
"status": "unaffected"
}
],
"version": "6.0",
"lessThan": "6.0.13",
"versionType": "custom"
}
],
"platforms": [
"Windows",
"MacOS"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "GlobalProtect App",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "6.0.14",
"status": "unaffected"
}
],
"version": "6.0",
"lessThan": "6.0.14",
"versionType": "custom"
}
],
"platforms": [
"Android",
"Chrome OS"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "GlobalProtect UWP App",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "6.3.3-h10",
"status": "unaffected"
}
],
"version": "6.3",
"lessThan": "6.3.3-h10",
"versionType": "custom"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "GlobalProtect App",
"versions": [
{
"status": "unaffected",
"version": "All",
"versionType": "custom"
}
],
"platforms": [
"iOS"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-13T19:16:59.260",
"references": [
{
"url": "https://security.paloaltonetworks.com/CVE-2026-0250",
"tags": [
"Vendor Advisory"
],
"source": "psirt@paloaltonetworks.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway.\n\n\n\nThe GlobalProtect app on iOS is not affected."
}
],
"lastModified": "2026-07-14T16:40:11.820",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "A27BA94F-A5CE-4D05-AAF3-6F1278F3478F",
"versionEndExcluding": "6.0.12",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "821399ED-2A5C-4684-841D-BE489E85FB72",
"versionEndExcluding": "6.0.13",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "518C5EB1-B8A3-4B05-B727-47EA7B1FE513",
"versionEndExcluding": "6.0.13",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "D8542C50-8CCA-41D4-9CC5-5DC199631340",
"versionEndExcluding": "6.0.15",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:chrome:*:*",
"vulnerable": true,
"matchCriteriaId": "6FC98EFE-3179-4EE2-927B-1674DBC1B6BC",
"versionEndExcluding": "6.0.15",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "C6CA9D61-7D4D-489F-9640-D88A30F6037A",
"versionEndExcluding": "6.1.14",
"versionStartIncluding": "6.1.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:chrome:*:*",
"vulnerable": true,
"matchCriteriaId": "541408B7-62AB-4A23-AD6B-8EB9298FBD0A",
"versionEndExcluding": "6.1.14",
"versionStartIncluding": "6.1.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "84C4C650-DBCF-488A-AD29-84347162D48B",
"versionEndExcluding": "6.2.8",
"versionStartIncluding": "6.2.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "98296E39-B40D-4F25-9D0C-C9CACFE25814",
"versionEndExcluding": "6.2.8",
"versionStartIncluding": "6.2.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:universal_windows_platform:*:*",
"vulnerable": true,
"matchCriteriaId": "3836E3A8-3329-4EA9-AE76-3F1A3A17BC81",
"versionEndExcluding": "6.3.3",
"versionStartIncluding": "6.3.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "3A842EBF-EA01-4D05-96C5-7F2061951423",
"versionEndExcluding": "6.3.3",
"versionStartIncluding": "6.3.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "034EDBA0-F7C4-40A3-AC7F-161126A4D74B",
"versionEndExcluding": "6.3.4",
"versionStartIncluding": "6.3.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:chrome:*:*",
"vulnerable": true,
"matchCriteriaId": "D6F2ED5D-CA4D-48DD-8B1A-F08D45061B90",
"versionEndExcluding": "6.3.4",
"versionStartIncluding": "6.3.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "F781BC4A-B907-4393-A94A-D200A0BD73E3"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "95312A9E-9204-451C-85F9-891312FDFAA4"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h1:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "77C49DC4-CC2B-46C3-9122-40B399E657A6"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h7:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "9F6A6D49-B2DE-4359-83B3-D3239559CE64"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h7:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "CDA02D18-0121-442D-844A-D7B8D70F4853"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "D8495DBE-5B93-495D-9726-E4360942464B"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "47AAC03D-0E33-430D-AB58-CABCC1546285"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:universal_windows_platform:*:*",
"vulnerable": true,
"matchCriteriaId": "0D7A9225-A2BA-4357-8048-A1D2E3047C15"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "8BD47595-78F1-4CD4-AD9A-572C1B128FD4"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h1:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "E4CF788E-01C0-4D49-9E83-EFD161E9B112"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h1:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "1BCA9A56-9AFB-4C97-B597-C3F1DC786A35"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "3E23B006-1A50-4ABA-A173-F784CEE443FD"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "D3632AD0-54EB-4CA4-AB41-983B6965B30E"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "8868A339-6229-487A-8D16-4B06ECB132AE"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h3:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "82E3F152-A98F-4B12-B9B7-8F2E3DB8A6A5"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h3:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "FB1C2ACF-8931-410A-BFE8-2E4DE3D15A0D"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h4:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "EC0A413D-5F2C-4FE8-ADE6-A78244A7E132"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h4:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "2C0EAAFC-5ED3-4D96-A0CE-EDBD4246CD7A"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h6:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "B7A8F2F7-85C7-4456-9E71-F94F3DF96356"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h6:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "7D4FFE1D-5707-4DC4-B783-46AAA5D8D037"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h7:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "7472FAD0-A40D-437A-82DA-70A7B959A62C"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h7:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "AFC6221C-3D39-4F51-86F4-826D7B72D4E5"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h8:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "B6C0F18B-802C-43D5-AEDD-05B7E5A53CED"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h8:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "EC8FBE7C-A3FE-4CBB-947D-F2BA1DB0D39C"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h9:*:*:*:universal_windows_platform:*:*",
"vulnerable": true,
"matchCriteriaId": "64157CC4-AADA-425B-B26E-C529A973A6DA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@paloaltonetworks.com"
}