CVE-2026-0288 Details
Description
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.
Multiple buffer overflow vulnerabilities have been identified in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software. These vulnerabilities allow an unauthenticated attacker with network access to cause a denial-of-service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The risk is highest when the User-ID TSA is exposed to the Internet or untrusted networks. However, this issue can be mitigated by restricting TSA connectivity to trusted internal IP addresses, as recommended in Palo Alto Networks' deployment guidelines. It's important to note that Panorama is not affected by these vulnerabilities.
Users can upgrade to the latest versions of PAN-OS or Prisma Access as specified in the product status section. For PAN-OS, the recommended versions are 12.1.7-h2, 12.1.8, 11.2.13, 11.1.16, and 10.2.18-h8. Prisma Access users should upgrade to 11.2.7-h18 or 10.2.10-h39, depending on their current version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-104023.html | siemens-SADP | |
| https://security.paloaltonetworks.com/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks pan-os | >= 10.2.0, < 10.2.7 >= 10.2.8, < 10.2.10 >= 10.2.11, < 10.2.13 >= 10.2.14, < 10.2.16 10.2.7 - 10.2.7 h1 10.2.7 h10 10.2.7 h11 10.2.7 h12 10.2.7 h13 10.2.7 h14 10.2.7 h15 10.2.7 h16 10.2.7 h17 10.2.7 h18 10.2.7 h19 10.2.7 h2 10.2.7 h20 10.2.7 h21 10.2.7 h22 10.2.7 h23 10.2.7 h24 10.2.7 h3 10.2.7 h32 10.2.7 h34 10.2.7 h35 10.2.7 h4 10.2.7 h5 10.2.7 h6 10.2.7 h7 10.2.7 h8 10.2.7 h9 10.2.10 - 10.2.10 h1 10.2.10 h10 10.2.10 h11 10.2.10 h12 10.2.10 h13 10.2.10 h14 10.2.10 h17 10.2.10 h18 10.2.10 h2 10.2.10 h21 10.2.10 h27 10.2.10 h3 10.2.10 h30 10.2.10 h31 10.2.10 h36 10.2.10 h37 10.2.10 h4 10.2.10 h5 10.2.10 h6 10.2.10 h7 10.2.13 - 10.2.13 h1 10.2.13 h10 10.2.13 h15 10.2.13 h16 10.2.13 h18 10.2.13 h2 10.2.13 h21 10.2.13 h22 10.2.13 h3 10.2.13 h4 10.2.13 h5 10.2.13 h7 10.2.16 - 10.2.16 h1 10.2.16 h4 10.2.16 h6 10.2.16 h7 10.2.16 h8 10.2.17 10.2.18 h1 10.2.18 h5 10.2.18 h6 10.2.18 h7 >= 11.1.0, < 11.1.4 >= 11.1.8, < 11.1.10 >= 11.1.11, < 11.1.13 >= 11.1.14, < 11.1.16 11.1.4 - 11.1.4 h1 11.1.4 h10 11.1.4 h11 11.1.4 h12 11.1.4 h13 11.1.4 h15 11.1.4 h17 11.1.4 h18 11.1.4 h2 11.1.4 h25 11.1.4 h27 11.1.4 h3 11.1.4 h32 11.1.4 h33 11.1.4 h34 11.1.4 h4 11.1.4 h5 11.1.4 h6 11.1.4 h7 11.1.4 h8 11.1.4 h9 11.1.5 11.1.6 - 11.1.6 h1 11.1.6 h10 11.1.6 h14 11.1.6 h17 11.1.6 h18 11.1.6 h19 11.1.6 h2 11.1.6 h20 11.1.6 h21 11.1.6 h22 11.1.6 h23 11.1.6 h25 11.1.6 h29 11.1.6 h3 11.1.6 h32 11.1.6 h33 11.1.6 h34 11.1.6 h4 11.1.6 h6 11.1.6 h7 11.1.10 - 11.1.10 h1 11.1.10 h10 11.1.10 h12 11.1.10 h21 11.1.10 h25 11.1.10 h26 11.1.10 h27 11.1.10 h28 11.1.10 h4 11.1.10 h5 11.1.10 h7 11.1.10 h9 11.1.13 - 11.1.13 h1 11.1.13 h2 11.1.13 h3 11.1.13 h5 11.1.13 h6 11.1.13 h7 11.1.13 h8 >= 11.2.0, < 11.2.4 >= 11.2.5, < 11.2.7 >= 11.2.8, < 11.2.10 >= 11.2.11, < 11.2.13 11.2.4 - 11.2.4 h1 11.2.4 h10 11.2.4 h11 11.2.4 h12 11.2.4 h14 11.2.4 h15 11.2.4 h17 11.2.4 h18 11.2.4 h2 11.2.4 h3 11.2.4 h4 11.2.4 h5 11.2.4 h6 11.2.4 h7 11.2.4 h8 11.2.4 h9 11.2.7 - 11.2.7 h1 11.2.7 h10 11.2.7 h11 11.2.7 h12 11.2.7 h13 11.2.7 h14 11.2.7 h15 11.2.7 h16 11.2.7 h17 11.2.7 h2 11.2.7 h3 11.2.7 h4 11.2.7 h7 11.2.7 h8 11.2.10 - 11.2.10 h1 11.2.10 h10 11.2.10 h2 11.2.10 h3 11.2.10 h4 11.2.10 h5 11.2.10 h6 11.2.10 h7 11.2.10 h8 11.2.10 h9 >= 12.1.2, < 12.1.4 >= 12.1.5, < 12.1.7 12.1.4 - 12.1.4 h2 12.1.4 h3 12.1.4 h5 12.1.4 h6 12.1.4 h7 12.1.7 - 12.1.7 h1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CVE Modified | siemens-SADP |
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |