CVE-2026-0288: PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent (Severity: HIGH)
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.
The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. .
Panorama is not impacted by this vulnerability.
Other sources
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.
The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only.).
Panorama is not impacted by this vulnerability.
— Palo Alto Networks
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8Fixed in 12.1.7-h2Fixed in 12.1.4-h8Fixed in 11.2.13Fixed in 11.2.10-h12Fixed in 11.2.7-h18Fixed in 11.2.4-h20Fixed in 11.1.16Fixed in 11.1.13-h9Fixed in 11.1.10-h30Fixed in 11.1.7-h8Fixed in 11.1.6-h35Fixed in 11.1.4-h35Fixed in 10.2.18-h8Fixed in 10.2.16-h9Fixed in 10.2.13-h23Fixed in 10.2.10-h39Fixed in 10.2.7-h36 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.7-h18Fixed in 10.2.10-h39 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.10-h39 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.13-h23 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.16-h9 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.7-h36 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.10-h30 or 11.1.16 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.13-h9 or 11.1.16 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.4-h35 or 11.1.16 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.6-h35 or 11.1.16 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.7-h8 or 11.1.16 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.10-h12 or 11.2.13 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.4-h20 or 11.2.13 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.7-h18 or 11.2.13 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h8 or 12.1.8 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.18-h8 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.1.16 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.13 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7-h2 or 12.1.8 or later - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.7-h18 or later - Compensating control
Restrict User-ID Terminal Server Agent (TSA) connectivity to only trusted internal IP addresses (best practice deployment guidelines referenced in the provided text) to minimize security risk.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0288?
The severity of CVE-2026-0288 is rated as critical with a score of 9.2.
How do I fix CVE-2026-0288?
To fix CVE-2026-0288, users should upgrade to the latest version of Palo Alto Networks PAN-OS or apply relevant patches provided by Palo Alto Networks.
What types of attacks can exploit CVE-2026-0288?
CVE-2026-0288 can be exploited to cause a denial of service (DoS) condition or potentially execute arbitrary code.
Who is affected by CVE-2026-0288?
Users of Palo Alto Networks PAN-OS and Prisma Access are affected by CVE-2026-0288.
What component is vulnerable in CVE-2026-0288?
The User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS is vulnerable in CVE-2026-0288.