Cybersecurity

Five Flaws in Palo Alto’s VPN, and a Disclosure Fight That Says More Than the Bugs

0

Security researcher Martijn van Ramesdonk has gone public with five vulnerabilities in Palo Alto Networks’ GlobalProtect, the VPN and endpoint agent running on countless corporate machines across Windows, macOS, and Linux. The bugs are serious on their own. But the more revealing part of this story is what happened after he reported them, and what it says about the state of vulnerability disclosure.

Start with the technical damage. Two of the five issues were folded into CVE-2026-0251, a set of local privilege-escalation flaws that let a low-privileged user on an endpoint climb all the way to SYSTEM on Windows or root on macOS and Linux. In plain terms, an attacker who already has a modest foothold on a machine can seize full control of it. The National Vulnerability Database rates it 7.8, a high score, though Palo Alto’s own advisory labels it merely medium, a gap that itself hints at the tension running through this whole affair.

The bug that should worry identity teams

The scariest finding is not the privilege escalation. Van Ramesdonk says he also worked out how to recover a user’s Active Directory password directly from the endpoint by abusing privileged GlobalProtect components. That matters far more than a typical local exploit, because a VPN client sits at a sensitive junction of the network, wired straight into the corporate identity system. Pull a domain password out of it and you are no longer talking about one compromised laptop; you are talking about a key to the wider network. Security software holding elevated privileges is exactly the kind of target where a bug does outsized damage.

When coordinated disclosure breaks down

Here is where the account turns into something bigger than a patch note. Van Ramesdonk reported all five issues in April. By his telling, Palo Alto quietly fixed the two that became CVE-2026-0251 without notifying or crediting him at first, two more were ruled out of scope for the bug bounty, and a fifth remains unpatched. He describes more than 40 emails with the vendor’s security team and a string of shifting deadlines, and calls the experience a symptom of a broken coordination model rather than a technical one.

To be fair to Palo Alto, the picture is not one-sided. The company did patch the flaws, its advisory now credits him by name alongside another researcher, it says it is aware of no exploitation in the wild, and bug-bounty scope disputes and deadline friction are ordinary, contested features of disclosure everywhere. Four proof-of-concept exploits are now public, while the fifth is being held back pending a fix, and patched builds are available across the affected 6.0, 6.2, and 6.3 branches, which is the practical point for anyone running GlobalProtect: update now.

The researcher’s broader argument is the one worth sitting with. AI is making it dramatically faster to find bugs, but validating, fixing, and crediting them still runs at human speed, on human processes. That mismatch is only going to widen. So what happens when researchers can surface flaws faster than vendors can responsibly handle them? Finding the bug was never really the hard part. Handling it well, at scale, without burning the people who report it, is the problem no automation is going to solve.

ReliaQuest Got Phished by the Very Playbook It Had Just Warned About

Previous article

WATER Raised $2.5M to Make Your Chair and Bed Respond to Your Body

Next article

You may also like

Comments

Comments are closed.