CVE-2026-0228

PAN-OS: Improper Validation of Terminal Server Agent Certificate

Severity
Low 1.3
CVSS 4.0
Exploited
Not listed
EPSS
0.002
9.5th percentile
Discovered by
Third party
Vendor-published field
Published
Feb 11, 2026
Assigned by palo_alto

Description

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

Paolo Nero of Wellcomm Engineering

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 No action needed. PAN-OS 11.2 11.2.0 through 11.2.7 Upgrade to 11.2.8 or later. PAN-OS 11.1 11.1.0 through 11.1.10 Upgrade to 11.1.11 or later. PAN-OS 10.2 10.2.0 through 10.2.16 Upgrade to 10.2.17 or later. All older   Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 11.2 on PAN-OS 11.2.0 through 11.2.7 Upgrade to 11.2.7-h10 or later. Prisma Access 10.2 on PAN-OS 10.2.0 through 10.2.10 Upgrade to 10.2.10-h28 or later.

Something wrong here?