CVE-2025-0135: Palo Alto Networks Globalprotect
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Affected products
- Palo Alto Networks Globalprotect: from 6.0.0, before 6.2.8 (fixed in 6.2.8); from 6.3.0, before 6.3.3 (fixed in 6.3.3)
Published 2025-05-14. Last modified 2026-06-17.