Palo Alto Networks PAN-OS: buffer overflow
High7.2CVE-2026-0288 · Published Jul 8, 2026 · updated Aug 11, 2026
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| PAN-OS Product | >= 12.1.0, < 12.1.8 | 12.1.8 |
| >= 11.2.0, < 11.2.13 | 11.2.13 | |
| >= 11.1.0, < 11.1.16 | 11.1.16 | |
| >= 10.2.0, < 10.2.7-h36 | 10.2.7-h36 | |
| Prisma Access Product | >= 11.2.0, < 11.2.7-h18 | 11.2.7-h18 |
| >= 10.2.0, < 10.2.10-h39 | 10.2.10-h39 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-787
More Palo Alto Networks advisories
All Palo Alto Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 9 | Palo Alto Networks PAN-OS: server-side request forgery | Medium4.7 | 12.1.8+3 more |
| Jul 9 | Palo Alto Networks PAN-OS: authentication bypass | Medium4.5 | 12.1.8+3 more |
| Jul 9 | Palo Alto Networks PAN-OS: unauthenticated attacker could the management web... | Low2.7 | 12.1.8+3 more |
| Jul 9 | Palo Alto Networks PAN-OS: information disclosure | Low2.1 | 12.1.8+3 more |
| Jul 9 | Palo Alto Networks PAN-OS: unauthenticated attacker could bypass firewall... | Low1.7 | 12.1.8+5 more |
| Jul 9 | Palo Alto Networks PAN-OS: cross-site scripting | Low1.3 | 12.1.8+3 more |