CVE-2026-0288

HIGHCVSS 7.5/10EPSS 0.84%

Last modified

CVE-2026-0288 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.

Description

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
PaloaltonetworksPan-Os>= 10.2.0, < 10.2.7—
PaloaltonetworksPan-Os>= 10.2.8, < 10.2.10—
PaloaltonetworksPan-Os>= 10.2.11, < 10.2.13—
PaloaltonetworksPan-Os>= 10.2.14, < 10.2.16—
PaloaltonetworksPan-Os10.2.7—
PaloaltonetworksPan-Os10.2.10—
PaloaltonetworksPan-Os10.2.13—
PaloaltonetworksPan-Os10.2.16—
PaloaltonetworksPan-Os10.2.17—
PaloaltonetworksPan-Os10.2.18H1
PaloaltonetworksPan-Os>= 11.1.0, < 11.1.4—
PaloaltonetworksPan-Os>= 11.1.8, < 11.1.10—
PaloaltonetworksPan-Os>= 11.1.11, < 11.1.13—
PaloaltonetworksPan-Os>= 11.1.14, < 11.1.16—
PaloaltonetworksPan-Os11.1.4—
PaloaltonetworksPan-Os11.1.5—
PaloaltonetworksPan-Os11.1.6—
PaloaltonetworksPan-Os11.1.10—
PaloaltonetworksPan-Os11.1.13—
PaloaltonetworksPan-Os>= 11.2.0, < 11.2.4—
PaloaltonetworksPan-Os>= 11.2.5, < 11.2.7—
PaloaltonetworksPan-Os>= 11.2.8, < 11.2.10—
PaloaltonetworksPan-Os>= 11.2.11, < 11.2.13—
PaloaltonetworksPan-Os11.2.4—
PaloaltonetworksPan-Os11.2.7—
PaloaltonetworksPan-Os11.2.10—
PaloaltonetworksPan-Os>= 12.1.2, < 12.1.4—
PaloaltonetworksPan-Os>= 12.1.5, < 12.1.7—
PaloaltonetworksPan-Os12.1.4—
PaloaltonetworksPan-Os12.1.7—

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2026-0288?
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.
How severe is CVE-2026-0288?
CVE-2026-0288 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.84% probability of exploitation in the next 30 days.
How do I fix CVE-2026-0288?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-0288?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST