PAN-OS
CVE-2026-0288: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cloud NGFW (AWS, Azure) | Not affected |
| PAN-OS 12.1 | 12.1.4-h8, 12.1.7-h2, 12.1.8 or later |
| PAN-OS 11.2 | 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, 11.2.13 or later |
| PAN-OS 11.1 | 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16 or later |
| PAN-OS 10.2 | 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8 or later |
| Prisma Access 11.2 | 11.2.7-h18 or later |
| Prisma Access 10.2 | 10.2.10-h39 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.
The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only.).
Panorama is not impacted by this vulnerability.
Am I affected?
This issue only affects PAN-OS devices with at least one Terminal Server Agent (TSA) entry configured
To check if a PAN-OS device has a Terminal Server Agent configured, navigate to:
Device > User Identification > Terminal Server Agents (https://docs.paloaltonetworks.com/ngfw/help/12-1/user-identification/device-user-identification-terminal-services-agents)
Workarounds
The vast majority of firewalls already follow Palo Alto Networks' and industry best practices. However, if you have not already, we strongly recommend that you restrict your User-ID Terminal Server Agent connectivity to only trusted internal IP addresses according to our best practice deployment guidelines (https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only.)
Exploitation
Palo Alto Networks is not aware of any malicious exploitation of these issues.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.