A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint agent used across thousands of enterprise networks worldwide. The disclosure, published through a dedicated research site, has reignited debate over how vendors handle vulnerability reports even when researchers follow coordinated disclosure norms. According to the researcher Martijn van Ramesdonk, the five issues were originally submitted to Palo Alto Networks in early April 2026, and two of them were eventually folded into CVE-2026-0251, a set of local privilege escalation flaws in the GlobalProtect app. Palo Alto’s own advisory confirms that the bugs allow a local,...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!