One specially generated network request can turn the Palo Alto Networks firewall from a security tool to a penetration point. Vulnerability in PAN-OS allows a remote attacker without a record to disrupt the operation of the device, and if a successful attack, potentially perform an arbitrary code.
The error received the CVE-2026-0288 identifier and affects the User-ID Terminal Server Agent component, abridged with TSA. Several buffer overflows allow you to damage memory when handling malicious network traffic. The attacker is enough to access the address and port of the TSA, the identity and user action are not required.
Palo Alto Networks assigned vulnerabilities a high level of danger and maximum urgency of fixing. The basic score of CVSS 4.0 reaches 9.2 points, and the score adjusted to take into account the current threat is 7.2 points. Systems are at the highest risk in which the Terminal Server Agent port is available from the Internet or an untrusted network.
Only devices that are at least one Terminal Server Agent record is configured. Administrators can check the configuration in the Device, User Identification, Terminal Server Agents. The centralized Panorama management platform is not affected. Cloud-line cloud-run cloud-run cloud-runs at AWS also does not require a fix, and the owners of the Azure will have to check the notifications from Palo Alto Networks.
The problem touches on several issues of PAN-OS 10.2, 11.1, 11.2 and 12.1, as well as Prisma Access 10.2 and 11.2. The company has already released the corrected assemblies, but the desired number depends on the specific branch and the installed package of fixes. For older unsupported versions, the developer recommends switching to an actual protected release. Prisma Access customers will be updated during the nearest scheduled service, if necessary, the installation can be requested earlier through the support service.
Before installing the Palo Alto Networks update, it advises to allow the connection to Terminal Server Agent only to trusted internal IP addresses and completely close the corresponding port from the Internet. Such a setting significantly reduces the attack surface, although it does not replace the correction.
At the time of publication, Palo Alto Networks found no signs of operation of CVE-2026-0288 in real attacks. The vulnerability was found and handed over to the developer by researcher Liang Zhu.
The error received the CVE-2026-0288 identifier and affects the User-ID Terminal Server Agent component, abridged with TSA. Several buffer overflows allow you to damage memory when handling malicious network traffic. The attacker is enough to access the address and port of the TSA, the identity and user action are not required.
Palo Alto Networks assigned vulnerabilities a high level of danger and maximum urgency of fixing. The basic score of CVSS 4.0 reaches 9.2 points, and the score adjusted to take into account the current threat is 7.2 points. Systems are at the highest risk in which the Terminal Server Agent port is available from the Internet or an untrusted network.
Only devices that are at least one Terminal Server Agent record is configured. Administrators can check the configuration in the Device, User Identification, Terminal Server Agents. The centralized Panorama management platform is not affected. Cloud-line cloud-run cloud-run cloud-runs at AWS also does not require a fix, and the owners of the Azure will have to check the notifications from Palo Alto Networks.
The problem touches on several issues of PAN-OS 10.2, 11.1, 11.2 and 12.1, as well as Prisma Access 10.2 and 11.2. The company has already released the corrected assemblies, but the desired number depends on the specific branch and the installed package of fixes. For older unsupported versions, the developer recommends switching to an actual protected release. Prisma Access customers will be updated during the nearest scheduled service, if necessary, the installation can be requested earlier through the support service.
Before installing the Palo Alto Networks update, it advises to allow the connection to Terminal Server Agent only to trusted internal IP addresses and completely close the corresponding port from the Internet. Such a setting significantly reduces the attack surface, although it does not replace the correction.
At the time of publication, Palo Alto Networks found no signs of operation of CVE-2026-0288 in real attacks. The vulnerability was found and handed over to the developer by researcher Liang Zhu.