AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-0288

HIGH · CVSS 7.5 EPSS 0.84%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) of Palo Alto Networks PAN-OS can be exploited by unauthenticated attackers with network access to trigger a denial of service (DoS) or potentially execute arbitrary code through specially crafted traffic. Organizations using PAN-OS should prioritize patching this vulnerability, especially if the User-ID TSA is accessible from untrusted networks, to mitigate the risk of exploitation. Following best practices by restricting TSA connectivity to trusted internal IP addresses can help minimize the security risk.

CVE
CVE-2026-0288
Severity
HIGH
CVSS
7.5
EPSS
0.84%
Palo Alto PAN-OS

Original NVD Description

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)