CVE-2026-0288 – Palo Alto Networks Cloud NGFW

CVSS 7.5 IMPORTANT High with EoP or RCE – Expedited Deployment

“A network service exposed to the wrong audience can quickly become an attacker’s entry point.”

Palo Alto Networks has released a security update for Cloud NGFW to address CVE-2026-0288, a buffer overflow vulnerability (CWE-787) in the User-ID Terminal Server Agent (TSA) component of PAN-OS. An unauthenticated attacker with network access could exploit the vulnerability by sending specially crafted network traffic, potentially causing a denial-of-service condition or achieving arbitrary code execution. The risk is significantly reduced when TSA connectivity is restricted to trusted internal IP addresses. Panorama is not affected by this vulnerability.

The CVSS score is 7.2, which is High severity. Based on the information provided, there is no verified exploitation associated with this vulnerability. Because the issue could potentially lead to remote code execution, organizations should prioritize applying the available security update and follow Palo Alto Networks' recommended deployment practices.

Key Details

Affected Product
Paloaltonetworks Pan-os
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-787
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.