Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-0298

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 8.5%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-0298


Contact Us

Shodan ® - All rights reserved