<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Prisma Access (12.1.2-12.1.*, 11.2.0-11.2.*, 10.2.0-10.2.*) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/prisma-access-12.1.2-12.1.-11.2.0-11.2.-10.2.0-10.2./</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 18:57:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/prisma-access-12.1.2-12.1.-11.2.0-11.2.-10.2.0-10.2./feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>GlobalProtect App Local Privilege Escalation Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-09-globalprotect-lpe/</link><pubDate>Wed, 09 Sep 2026 18:57:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-globalprotect-lpe/</guid><description>Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect application allow a local user to gain administrative privileges (SYSTEM/root) due to an untrusted search path issue.</description><content:encoded><![CDATA[<p>Palo Alto Networks has disclosed multiple local privilege escalation vulnerabilities (CVE-2026-0307) affecting the GlobalProtect app across Windows, macOS, and Linux platforms. The issue stems from CWE-426, an untrusted search path vulnerability, which allows a local non-administrative user to manipulate the execution flow of the application to run arbitrary commands with elevated privileges (NT AUTHORITY\SYSTEM on Windows and root on macOS/Linux).</p>
<p>The vulnerability is categorized as Medium severity and is documented with a CVSS-BT score of 5.9. Exploitation requires local access, and Palo Alto Networks has confirmed that there is currently no evidence of malicious exploitation in the wild. Full remediation requires a coordinated update of both the client-side GlobalProtect application and the server-side infrastructure (PAN-OS or Prisma Access). iOS, Android, and ChromeOS versions of the app are not affected.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a low-privileged local user to achieve full administrative control over the affected endpoint. This can lead to total system compromise, unauthorized data access, persistence installation, and further lateral movement within the network. The scope of impact is broad due to the ubiquity of GlobalProtect clients in enterprise environments.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the deployment of updated GlobalProtect client versions across all Windows, macOS, and Linux endpoints. Concurrently, schedule and execute upgrades for all affected PAN-OS and Prisma Access infrastructure components to ensure compatibility and full mitigation.</p>
<ul>
<li>Upgrade GlobalProtect App on Linux, macOS, and Windows to the versions specified in the Palo Alto Networks advisory (e.g., 6.3.3-h15 or later).</li>
<li>Update all PAN-OS and Prisma Access environments to the patched versions listed in the Solution section of the source advisory to ensure the infrastructure components are no longer vulnerable.</li>
<li>Audit endpoint security logs for unauthorized process execution or unexpected binary loading from untrusted directories.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category><category>vulnerability</category><category>privilege-escalation</category><category>endpoint</category></item></channel></rss>