CVE-2026-0228: PAN-OS: Improper Validation of Terminal Server Agent Certificate (Severity: LOW)
Published Feb 11, 2026
·Updated
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
Affected Software
2 affected componentsFixes available
Palo Alto Networks Cloud NGFW
Palo Alto Networks PAN-OS<11.2.8, =11.2.0, <11.1.11, =11.1.0, <10.2.17, =10.2.0
11.2.811.1.1110.2.17
Remediation
Mitigation
No known workarounds exist for this issue.
Information
VERSION MINOR VERSION SUGGESTED SOLUTION
Cloud NGFW No action needed.
PAN-OS 12.1 No action needed.
PAN-OS 11.2 11.2.0 through 11.2.7 Upgrade to 11.2.8 or later.
PAN-OS 11.1 11.1.0 through 11.1.10 Upgrade to 11.1.11 or later.
PAN-OS 10.2 10.2.0 through 10.2.16 Upgrade to 10.2.17 or later.
All older Upgrade to a supported fixed version.
unsupported
PAN-OS versions
Prisma Access 11.2 on PAN-OS 11.2.0 through 11.2.7 Upgrade to 11.2.7-h10 or later.
Prisma Access 10.2 on PAN-OS 10.2.0 through 10.2.10 Upgrade to 10.2.10-h28 or later.
Event History
Feb 11, 2026
Advisory Published
via Palo Alto Networks·05:00 PM
Data Sourced
via Palo Alto Networks·05:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-0228?
The severity of CVE-2026-0228 is classified as LOW.
2
Which products are affected by CVE-2026-0228?
CVE-2026-0228 affects Palo Alto Networks PAN-OS versions from 10.2.0 up to 10.2.17, 11.1.0 up to 11.1.11, and 11.2.0 up to 11.2.8.
3
How can I mitigate CVE-2026-0228?
Mitigation for CVE-2026-0228 involves upgrading to the recommended versions of PAN-OS, specifically 10.2.17, 11.1.11, or 11.2.8.
4
What type of vulnerability is CVE-2026-0228?
CVE-2026-0228 is classified as an improper certificate validation vulnerability.
5
What is the impact of CVE-2026-0228?
The impact of CVE-2026-0228 allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates.