CVE-2026-0250

HIGH

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with...

Affects 0 products across 4 vendors.

BCS3.01
CVSS 3.18.1
CVSS v45.2
EPSS0.4%
Percentile32th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

A low severity vulnerability affects Gateway systems (CVE-2026-0250). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.

BSID: BS-2026-GLOBAL-059144-I • Model: rule-based-v1 • Confidence: LOW

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-0250?
A low severity vulnerability affects Gateway systems (CVE-2026-0250). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
What is the CVSS score for CVE-2026-0250?
CVE-2026-0250 has CVSS 8.1 (High). Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-0250 actively exploited?
No confirmed active exploitation of CVE-2026-0250 as of 2026-07-15.
How do I remediate CVE-2026-0250?
Priority: MONITOR. PSIRT: [email protected]
What systems are affected by CVE-2026-0250?
CVE-2026-0250 affects: Gateway, Palo Alto, Palo Alto Networks, Processing.
Vulnerability Details
CVE IDCVE-2026-0250
BSIDBS-2026-GLOBAL-059144-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-13
Last Modified2026-07-14
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway. The GlobalProtect app on iOS is not affected.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway. The GlobalProtect app on iOS is not affected. CVSS vector: Not available.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Gateway —
Palo Alto —
Palo Alto Networks —
Processing —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 73 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceLOW
Enriched At2026-05-24
SHA-512 Audit Hashc0e5f3ce7ceea690fb5ef3f45da0195c78c04a15030d6544d3d113d233c072f493fb1b4f04740db5413a5db0edab2c001b3a63930fc12986cdd89f192d200e63
Related CVEs affecting Gateway
CVE-2024-50494 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Su... CVE-2025-58083 10.0 General Industrial Controls Lynx+ Gateway  is missing critical authenticatio... CVE-2002-1440 10.0 The Gateway GS-400 server has a default root password of "0001n" that can not... CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2026-32621 9.9 Apollo Federation is an architecture for declaratively composing APIs into a ...
View all Gateway CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →