← All Advisories

Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 7.5

Last refreshed2026-09-26

Status: NEW  |  Advisory ID: CVE-2026-0288

Key Details

CVECVE-2026-0288
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsPalo Alto Networks PAN-OS
Classified asCWE-787 (Out-of-bounds Write)
Exploitation prediction (EPSS)0.83% probability of exploitation in the next 30 days (56% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksPAN-OS
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.

The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. .

Panorama is not impacted by this vulnerability.

What to Do

Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0288
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0288
Vendor advisoryhttps://security.paloaltonetworks.com/