CVE-2026-0228

PAN-OS: Improper Validation of Terminal Server Agent Certificate

Severity
Low 1.3
CVSS 4.0
Exploited
Not listed
EPSS
0.002
8.6th percentile
Discovered by
Third party
Published by the vendor
Published
Feb 11, 2026
Assigned by palo_alto

Description

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

Paolo Nero of Wellcomm Engineering

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 No action needed. PAN-OS 11.2 11.2.0 through 11.2.7 Upgrade to 11.2.8 or later. PAN-OS 11.1 11.1.0 through 11.1.10 Upgrade to 11.1.11 or later. PAN-OS 10.2 10.2.0 through 10.2.16 Upgrade to 10.2.17 or later. All older   Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 11.2 on PAN-OS 11.2.0 through 11.2.7 Upgrade to 11.2.7-h10 or later. Prisma Access 10.2 on PAN-OS 10.2.0 through 10.2.10 Upgrade to 10.2.10-h28 or later.