Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3510 articles · 182400 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-0288PATCHED
Palo Alto Networks · Cloud NGFW

PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

Description

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.

Affected Products

VendorProductVersions
Palo Alto NetworksCloud NGFW12.1.0, 11.2.0, 11.1.0, 10.2.0, 11.2.0, 10.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
palo alto networkspan-osmitre_affected90%
palo alto networksprisma accessmitre_affected90%

References

  • https://security.paloaltonetworks.com/

Related News (4 articles)

Tier D
BleepingComputer7d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
→ No new info (linked only)
Tier D
SecurityWeek20d ago
Palo Alto Networks Patches 13 Vulnerabilities
→ No new info (linked only)
Tier B
BSI Advisories21d ago
[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB21d ago
CVE-2026-0288 | Palo Alto PAN-OS User-ID Terminal Server Agent buffer overflow
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
All12.1.811.2.1311.1.1610.2.7-h3611.2.7-h1810.2.10-h39
CWECWE-787
PublishedJul 8, 2026
Last enriched21d ago
Trending Score17
Source articles4
Independent4
Info Completeness7/14
Missing: versions, cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-0300EXP
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Trending: 111
NONECVE-2026-0257EXP
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Trending: 41
NONECVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Trending: 18
CRITICALCVE-2026-0284EXP
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
Trending: 3
HIGHCVE-2026-0286EXP
PAN-OS: Authenticated Command Injection in CLI
Trending: 3

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 8, 2026
Discovered by ZDM
Jul 8, 2026
Patch Available
Jul 9, 2026