Palo Alto Networks disclosed a set of buffer overflow vulnerabilities on July 8, 2026, affecting the User-ID Terminal Server Agent (TSA) component within PAN-OS.
Tracked as CVE-2026-0288, the flaw carries a CVSS v4.0 score of 7.2 (High) and allows an unauthenticated, network-based attacker to trigger a denial-of-service condition or potentially execute arbitrary code through specially crafted network traffic.
The TSA component helps PAN-OS firewalls map IP addresses to usernames in Terminal Server and Citrix environments, a critical function for enforcing user-based security policies.
PAN-OS Flaw CVE-2026-0288
Because the vulnerability requires no authentication and no user interaction, an attacker positioned on the network with access to the TSA service could exploit it remotely.
The CVSS 4.0 vector highlights a network attack, low attack complexity, and no privileges required, though it does require “attack requirements” to be met, meaning the attacker needs the TSA service to be reachable and listening.
Palo Alto Networks rates the impact on product confidentiality, integrity, and availability as High, reflecting the seriousness of a successful exploit that could compromise the firewall itself rather than just crash a service.
The vulnerability spans multiple PAN-OS release trains, including versions 10.2, 11.1, 11.2, and 12.1, as well as certain Prisma Access deployments.
Cloud NGFW on AWS is unaffected, while Cloud NGFW on Azure remains vulnerable unless customers were separately contacted by Palo Alto Networks. Panorama management appliances are explicitly excluded from this vulnerability.
Fixed versions include:
- PAN-OS 10.2: 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, and 10.2.18-h8 or later
- PAN-OS 11.1: 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, and 11.1.16 or later
- PAN-OS 11.2: 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, and 11.2.13 or later
- PAN-OS 12.1: 12.1.4-h8, 12.1.7-h2, and 12.1.8 or later
- Prisma Access: 10.2.10-h39 and 11.2.7-h18 or later, depending on deployment version
Organizations running unpatched versions within these trains should treat patching as an immediate priority, particularly given the “Urgency: Highest” rating attached to this advisory.
Palo Alto Networks emphasizes that restricting TSA connectivity to trusted internal IP addresses substantially reduces exposure, aligning with the vendor’s long-standing best-practice deployment guidance for Terminal Services Agents.
This network segmentation approach won’t eliminate the underlying flaw, but it closes the practical attack surface for external or lateral-movement attackers who lack access to the internal segment where TSA operates.
“This vulnerability is a reminder that identity infrastructure sitting behind the firewall isn’t automatically safe by association,” said. “Security teams often assume that because a service supports core firewall functions, it inherits the firewall’s hardened perimeter.
In reality, agent-based components like TSA frequently become soft targets precisely because they’re overlooked during network segmentation reviews.”
As of publication, Palo Alto Networks lists the exploit maturity as “unreported,” meaning no known public exploitation has been observed. However, the absence of a public proof of concept doesn’t diminish the urgency here.
The vulnerability’s low attack complexity and lack of required privileges make it an attractive target once technical details or exploit code circulate.
Mitigation
Security teams managing PAN-OS deployments should prioritize inventorying which firewalls run the TSA component, confirming that network segmentation restricts TSA access to trusted zones, and scheduling patching to the fixed releases listed above without delay.
Given Palo Alto Networks’ recent history with actively exploited firewall vulnerabilities, defenders should not wait for confirmed in-the-wild exploitation before acting.