Palo Alto Networks has published a Thursday advisory disclosing 13 vulnerabilities across PAN-OS and Prisma Access, led by CVE-2026-0288 — a high-severity, highest-urgency buffer-overflow chain in the User-ID Terminal Server Agent (TSA) that can hand an unauthenticated attacker remote code execution across the vendor's next-generation firewalls. The company says it is not aware of active exploitation, but the CVSS-B 9.2 score and network-only attack path put the fix at the top of every firewall admin's Friday queue.
Inside CVE-2026-0288
The flaw sits in multiple buffer overflows in the User-ID TSA component of PAN-OS. Attackers with network access to the configured TSA IP and port — no credentials or user interaction required — can send a malformed packet to corrupt memory, trigger a denial-of-service crash, or in the worst case achieve remote code execution. Affected trains include PAN-OS 12.1 before 12.1.4-h8/12.1.7-h2/12.1.8, 11.2 before 11.2.4-h20/11.2.7-h18/11.2.10-h12/11.2.13, 11.1 before 11.1.4-h35 through 11.1.16, and every 10.2 build before 10.2.7-h36/10.2.18-h8. Prisma Access 11.2.0 and 10.2.0 carry a medium-severity variant. Panorama and Cloud NGFW on AWS are not affected.
Twelve More Fixes: VPN Interception, Root Command Execution
The batch also patches seven medium-severity PAN-OS bugs and five low-severity flaws. Two of the medium tier sit in the Prisma Access Agent and let attackers stage man-in-the-middle interception of VPN traffic and bypass data-loss-prevention policies — the sleeper risk in this batch for organisations that lean on Prisma Access to secure a remote workforce. Other medium-severity issues let authenticated administrators execute OS commands as root, send unauthorised requests from the firewall to internal services or bypass authentication, escalation paths that raise the ceiling once an attacker already has admin access.
Mitigation and Prisma Access Timing
Palo Alto Networks recommends immediate upgrades across every affected branch, with fixed builds listed in the CVE-2026-0288 advisory. As an interim measure, admins should restrict TSA connectivity to trusted internal IPs per the vendor's best-practice deployment guide — a mitigation that drops CVSS-B from 9.2 to 7.7 but does not eliminate the underlying bug. Prisma Access customers will be upgraded during their next scheduled maintenance window; those needing an accelerated patch can request an on-demand upgrade through support. Security researcher Liang Zhu is credited with the private disclosure.
Pattern-Matching to the AI-Era Threat Landscape
The Palo Alto Networks patch cycle lands the same week security firm Sysdig documented JADEPUFFER, the first end-to-end AI-agent ransomware attack, and after the EU Commission unveiled a joint AI-and-cybersecurity action plan with pre-market model testing. With attackers moving faster from disclosure to exploitation — a warning Five Eyes issued earlier this year — every unauthenticated network-reachable firewall bug now compresses the window admins have to patch before opportunistic scanning begins.
Reporting based on coverage from Cyber Security News, SQ Magazine, SecurityWeek, HKCERT and the Palo Alto Networks security advisory.
