Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 1 advisory

CVE-2026-0288

CVE-2026-0288: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

1 advisory
  • Advisory severityCritical9.2

    Critical [CVE-2026-0288] PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

    CVE-2026-0288Source published

    Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines. Panorama is not impacted by this vulnerability. Affected products named by the advisory: Prisma Access.

    Affected products in this advisory
    • PAN-OS
    • Prisma Access
    Source-reported affected versions
    • PAN-OS < 12.1.8
    • PAN-OS < 11.2.13
    • PAN-OS < 11.1.16
    • PAN-OS < 10.2.7-h36

    2 more entries in the full advisory.

    Source-reported fixed versions
    • PAN-OS >= 12.1.8
    • PAN-OS >= 12.1.7-h2
    • PAN-OS >= 12.1.4-h8
    • PAN-OS >= 11.2.13

    16 more entries in the full advisory.

    Mitigation guidance
    • VersionMinor VersionSuggested SolutionCloud NGFWNo action needed.
    • PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later.
    Workarounds
    • The vast majority of firewalls already follow Palo Alto Networks' and industry best practices.
    • However, if you have not already, we strongly recommend that you restrict your User-ID Terminal Server Agent connectivity to only trusted internal IP addresses according to our best practice deployment guidelines

Android app · Google Play

Monitor future Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery