CVE-2026-0288

PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

Severity
High 7.2
CVSS 4.0
Exploited
Not listed
EPSS
0.008
54.5th percentile
Discovered by
Third party
Published by the vendor
Published
Jul 8, 2026
Assigned by palo_alto

Description

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.

Weakness: CWE-787

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

Liang Zhu

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFWNo action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN-OS 11.2 11.2.0 through 11.2.12 Upgrade to 11.2.13 or later. 11.2.0 through 11.2.10-h* Upgrade to 11.2.10-h12 or 11.2.13 or later. 11.2.0 through 11.2.7-h* Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h20 or 11.2.13 or later. PAN-OS 11.1 11.1.0 through 11.1.15 Upgrade to 11.1.16 or later. 11.1.0 through 11.1.13-h* Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.0 through 11.1.10-h* Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.0 through 11.1.7-h* Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.0 through 11.1.6-h* Upgrade to 11.1.6-h35 or 11.1.16 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h35 or 11.1.16 or later. PAN-OS 10.2 10.2.0 through 10.2.18-h* Upgrade to 10.2.18-h8 or later.  10.2.0 through 10.2.16-h*Upgrade to 10.2.16-h9 or later. 10.2.0 through 10.2.13-h* Upgrade to 10.2.13-h23 or later. 10.2.0 through 10.2.10-h* Upgrade to 10.2.10-h39 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h36 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version. Prisma Access 11.2 11.2.0 through 11.2.7 Upgrade to 11.2.7-h18 or later.* Prisma Access 10.2 10.2.0 through 10.2.10 Upgrade to 10.2.10-h39 or later.* * See the note under Product Status for information regarding Prisma Access upgrades.