CVE-2025-0118: Palo Alto Networks Globalprotect

High severity, CVSS 8.0. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device. This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.

Affected products

  • Palo Alto Networks Globalprotect: from 6.0.0, before 6.0.11 (fixed in 6.0.11); from 6.1.0, before 6.1.6 (fixed in 6.1.6); from 6.2.0, before 6.2.5 (fixed in 6.2.5); from 6.3.0, before 6.3.3 (fixed in 6.3.3)

Published 2025-03-12. Last modified 2026-06-17.