Palo Alto Networks Patches Critical PAN-OS CVE-2026-0288 in 13-Bug Batch

Palo Alto Networks has disclosed 13 PAN-OS and Prisma Access vulnerabilities led by CVE-2026-0288, an unauthenticated buffer-overflow chain in the User-ID Terminal Server Agent that hands attackers remote code execution across next-generation firewalls.

Key Takeaways

  • Palo Alto Networks disclosed 13 vulnerabilities across PAN-OS and Prisma Access, led by CVE-2026-0288, a CVSS-B 9.2 buffer-overflow chain in the User-ID Terminal Server Agent enabling unauthenticated remote code execution.
  • CVE-2026-0288 affects PAN-OS 12.1, 11.2, 11.1 and 10.2 branches before their fixed builds; Prisma Access 11.2.0 and 10.2.0 carry a medium-severity variant, while Panorama and Cloud NGFW on AWS are unaffected.
  • The batch also fixes seven medium and five low-severity bugs, including Prisma Access Agent flaws allowing VPN traffic man-in-the-middle interception and DLP bypass, plus root command execution paths for authenticated admins.
  • No active exploitation is known; interim mitigation is restricting TSA connectivity to trusted internal IPs, which lowers CVSS-B from 9.2 to 7.7 but does not remove the flaw.
  • Prisma Access customers get patched at their next scheduled maintenance window, with on-demand upgrades available via support; researcher Liang Zhu privately disclosed the flagship bug.

Palo Alto Networks Patches Critical PAN-OS CVE-2026-0288 in 13-Bug Batch

Palo Alto Networks has published a Thursday advisory disclosing 13 vulnerabilities across PAN-OS and Prisma Access, led by CVE-2026-0288 — a high-severity, highest-urgency buffer-overflow chain in the User-ID Terminal Server Agent (TSA) that can hand an unauthenticated attacker remote code execution across the vendor's next-generation firewalls. The company says it is not aware of active exploitation, but the CVSS-B 9.2 score and network-only attack path put the fix at the top of every firewall admin's Friday queue.

Inside CVE-2026-0288

The flaw sits in multiple buffer overflows in the User-ID TSA component of PAN-OS. Attackers with network access to the configured TSA IP and port — no credentials or user interaction required — can send a malformed packet to corrupt memory, trigger a denial-of-service crash, or in the worst case achieve remote code execution. Affected trains include PAN-OS 12.1 before 12.1.4-h8/12.1.7-h2/12.1.8, 11.2 before 11.2.4-h20/11.2.7-h18/11.2.10-h12/11.2.13, 11.1 before 11.1.4-h35 through 11.1.16, and every 10.2 build before 10.2.7-h36/10.2.18-h8. Prisma Access 11.2.0 and 10.2.0 carry a medium-severity variant. Panorama and Cloud NGFW on AWS are not affected.

Twelve More Fixes: VPN Interception, Root Command Execution

The batch also patches seven medium-severity PAN-OS bugs and five low-severity flaws. Two of the medium tier sit in the Prisma Access Agent and let attackers stage man-in-the-middle interception of VPN traffic and bypass data-loss-prevention policies — the sleeper risk in this batch for organisations that lean on Prisma Access to secure a remote workforce. Other medium-severity issues let authenticated administrators execute OS commands as root, send unauthorised requests from the firewall to internal services or bypass authentication, escalation paths that raise the ceiling once an attacker already has admin access.

Palo Alto Networks patches 13 PAN-OS vulnerabilities on July 8, 2026

Mitigation and Prisma Access Timing

Palo Alto Networks recommends immediate upgrades across every affected branch, with fixed builds listed in the CVE-2026-0288 advisory. As an interim measure, admins should restrict TSA connectivity to trusted internal IPs per the vendor's best-practice deployment guide — a mitigation that drops CVSS-B from 9.2 to 7.7 but does not eliminate the underlying bug. Prisma Access customers will be upgraded during their next scheduled maintenance window; those needing an accelerated patch can request an on-demand upgrade through support. Security researcher Liang Zhu is credited with the private disclosure.

Pattern-Matching to the AI-Era Threat Landscape

The Palo Alto Networks patch cycle lands the same week security firm Sysdig documented JADEPUFFER, the first end-to-end AI-agent ransomware attack, and after the EU Commission unveiled a joint AI-and-cybersecurity action plan with pre-market model testing. With attackers moving faster from disclosure to exploitation — a warning Five Eyes issued earlier this year — every unauthenticated network-reachable firewall bug now compresses the window admins have to patch before opportunistic scanning begins.

Reporting based on coverage from Cyber Security News, SQ Magazine, SecurityWeek, HKCERT and the Palo Alto Networks security advisory.

Category: Cyber Security

Tags: Security Cybersecurity CVE

Related Articles

Frequently Asked Questions

What is CVE-2026-0288 and how dangerous is it?

CVE-2026-0288 is a set of buffer overflows in the User-ID Terminal Server Agent of PAN-OS. An unauthenticated attacker with network access to the configured TSA IP and port can send a malformed packet to crash the firewall or achieve remote code execution. It carries a CVSS-B score of 9.2, though no active exploitation has been reported.

Which products and versions are affected?

Affected trains include PAN-OS 12.1 before 12.1.4-h8/12.1.7-h2/12.1.8, 11.2 before 11.2.4-h20/11.2.7-h18/11.2.10-h12/11.2.13, 11.1 before 11.1.4-h35 through 11.1.16, and all 10.2 builds before 10.2.7-h36/10.2.18-h8. Prisma Access 11.2.0 and 10.2.0 have a medium-severity variant. Panorama and Cloud NGFW on AWS are not affected.

What should admins do if they cannot patch immediately?

Palo Alto Networks recommends restricting TSA connectivity to trusted internal IP addresses per its best-practice deployment guide. This lowers the CVSS-B score from 9.2 to 7.7 but does not eliminate the underlying vulnerability, so upgrading to a fixed build remains essential.

What other flaws were fixed in the 13-bug batch?

Seven medium and five low-severity issues were patched, including two Prisma Access Agent bugs enabling man-in-the-middle interception of VPN traffic and data-loss-prevention bypass, plus flaws letting authenticated administrators run OS commands as root, send unauthorised requests to internal services, or bypass authentication.