August 25, 2026
- Five GlobalProtect findings disclosed publicly, ranging from local privilege escalation to recovery of Active Directory credentials from the endpoint agent. Reported to Palo Alto in early April; two were addressed under CVE-2026-0251 (globalunprotect.io). · Vulnerabilities & Exploits
in The Rogue Agent Staged an Apology, Then Pushed More Malware