Critical Privilege Escalation Flaw Discovered in GlobalProtect App
PremiumGlobalProtect (Palo Alto Networks) has local privilege escalation flaws (CVE-2026-0251) enabling local code execution and privilege gains.

Loading
§The archiveMon · Wed · FriM · W · F
Every dispatch we've sent. AI-curated, human-reviewed, from 50+ cybersecurity sources.
Follow on LinkedInGlobalProtect (Palo Alto Networks) has local privilege escalation flaws (CVE-2026-0251) enabling local code execution and privilege gains.
Ubiquiti patched 22 vulnerabilities in UniFi products, including three rated 10.0, requiring urgent firmware updates to prevent RCE.
ATF confirms a system compromise linked to Qilin ransomware claims affecting investigation-related data access.
CISA added six actively exploited vulnerabilities to its KEV catalog affecting Microsoft, Linux, Red Hat and Citrix products.
U.S. agencies disrupted a China-linked hacking platform (QTFY) used against military and critical infrastructure, seizing infrastructure domains.
Report finds ransomware remains a major threat to education, disrupting operations, data and remote learning access across institutions.
Critical Avada WordPress theme vulnerability enables unauthenticated zero-click PHP remote code execution on affected sites.
GPUThor Rowhammer technique bypasses NVIDIA ECC on RTX A6000 GPUs to escalate privileges and gain host root access.
CISA added a Microsoft SQL Server RCE (CVE-2019-1068) to KEV after observed exploitation allowing code execution under SQL Server service.
Boston Scientific reports global operational disruption and shipment delays after a cyber incident impacting IT systems.
Australian authorities arrested two suspects tied to TeamPCP supply-chain attacks that tampered with open-source developer tools.
PaperCut NG/MF zero-day is actively exploited across all versions; vendor issued emergency patches and confirmed customer incidents.
CISA mandates immediate patching of Citrix NetScaler (CVE-2026-8452) after active exploitation; federal agencies have an urgent deadline.
Massive DDoS disrupted Norway's government digital services, taking multiple public-facing systems offline.
US sanctions Iranian cyber actors while the UK discloses a cyber intrusion that disrupted a small power plant.
Get these articles delivered to your inbox.
Subscribe free