CVE-2026-0298 - GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Brief
CVE ID : CVE-2026-0298
Published : Aug. 13, 2026, 2:02 a. m.
- 1 hour, 2 minutes ago
Description : An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Severity: 5.2
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
