CVE-2026-0288 – Palo Alto Networks Cloud NGFW
“A network service exposed to the wrong audience can quickly become an attacker’s entry point.”
Palo Alto Networks has released a security update for Cloud NGFW to address CVE-2026-0288, a buffer overflow vulnerability (CWE-787) in the User-ID Terminal Server Agent (TSA) component of PAN-OS. An unauthenticated attacker with network access could exploit the vulnerability by sending specially crafted network traffic, potentially causing a denial-of-service condition or achieving arbitrary code execution. The risk is significantly reduced when TSA connectivity is restricted to trusted internal IP addresses. Panorama is not affected by this vulnerability.
The CVSS score is 7.2, which is High severity. Based on the information provided, there is no verified exploitation associated with this vulnerability. Because the issue could potentially lead to remote code execution, organizations should prioritize applying the available security update and follow Palo Alto Networks' recommended deployment practices.
Key Details
- Affected Product
- Paloaltonetworks Pan-os
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-787