PAN-OS

CVE-2026-0288: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityHIGHCVSS 4.0 9.2
EPSS0.83%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Cloud NGFW (AWS, Azure)Not affected
PAN-OS 12.112.1.4-h8, 12.1.7-h2, 12.1.8 or later
PAN-OS 11.211.2.4-h20, 11.2.7-h18, 11.2.10-h12, 11.2.13 or later
PAN-OS 11.111.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16 or later
PAN-OS 10.210.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8 or later
Prisma Access 11.211.2.7-h18 or later
Prisma Access 10.210.2.10-h39 or later

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.

The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only.).

Panorama is not impacted by this vulnerability.

Am I affected?

This issue only affects PAN-OS devices with at least one Terminal Server Agent (TSA) entry configured

To check if a PAN-OS device has a Terminal Server Agent configured, navigate to:

Device > User Identification > Terminal Server Agents (https://docs.paloaltonetworks.com/ngfw/help/12-1/user-identification/device-user-identification-terminal-services-agents)

Workarounds

The vast majority of firewalls already follow Palo Alto Networks' and industry best practices. However, if you have not already, we strongly recommend that you restrict your User-ID Terminal Server Agent connectivity to only trusted internal IP addresses according to our best practice deployment guidelines (https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only.)

Exploitation

Palo Alto Networks is not aware of any malicious exploitation of these issues.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.