CVE-2025-2183: Palo Alto Networks Global Protect Uwp App
Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.
Affected products
- Palo Alto Networks Global Protect Uwp App
- Palo Alto Networks Globalprotect App: from 6.3.0, before 6.3.3-h2 (6.3.3-c676) (fixed in 6.3.3-h2 (6.3.3-c676)); from 6.2.0, before 6.2.8-h3 (6.2.8-c263) (fixed in 6.2.8-h3 (6.2.8-c263)); version 6.1.0 only; version 6.0.0 only; from 6.3.0, before 6.3.3 (fixed in 6.3.3); from 6.2.0, before 11.1.10 (fixed in 11.1.10)
Published 2025-08-13. Last modified 2026-06-17.