HIGH 7.5

CVE-2026-0288: PAN-OS User-ID Terminal Server Agent Buffer Overflow (CVSS 7.5)

Palo Alto Networks PAN-OS contains multiple buffer overflow flaws in the User-ID Terminal Server Agent (TSA) component that can be exploited over the network without authentication. An attacker can send malformed network traffic to trigger a denial of service or potentially run arbitrary code on affected firewalls. However, the risk is substantially reduced if you follow Palo Alto's deployment guidance and restrict TSA connectivity to trusted internal IP addresses only. Panorama appliances are not affected.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-787
Affected products
190 configuration(s)
Published / Modified
2026-07-08 / 2026-08-11

NVD description (verbatim)

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability.

2 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-0288 involves out-of-bounds write vulnerabilities (CWE-787) in PAN-OS User-ID Terminal Server Agent. The flaws are triggered by specially crafted network packets sent to the TSA service. With no authentication required and low attack complexity, the vulnerability has a CVSS 3.1 score of 7.5 (HIGH). The attack vector is network-based with no user interaction needed. While the availability impact is high (denial of service), the CVSS vector indicates no direct confidentiality or integrity impact from the base vulnerability itself, though code execution remains a potential risk depending on memory layout and exploitation conditions.

Business impact

Organizations running affected PAN-OS versions face risk of firewall unavailability if exploited for denial of service, which could disrupt network traffic inspection, threat prevention, and security policy enforcement. If arbitrary code execution is achieved, attackers could potentially compromise the firewall's integrity and gain a foothold in the network perimeter. The actual risk varies significantly based on deployment architecture: organizations that expose TSA to untrusted networks face elevated exposure, while those following Palo Alto's recommended segmentation practices have substantially lower risk. Unpatched TSA exposure in edge or DMZ segments is particularly concerning.

Affected systems

Multiple versions of Palo Alto Networks PAN-OS are affected. Panorama management appliances are explicitly not vulnerable. You must verify which specific PAN-OS versions running TSA are present in your environment by consulting the official Palo Alto Networks security advisory, as patch availability varies by release branch and series.

Exploitability

This vulnerability requires network access to the User-ID Terminal Server Agent port but no prior authentication or user interaction. The attack complexity is low, meaning a general attacker with network reachability to TSA can attempt exploitation. Public exploit code has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog as of the data snapshot. However, the relative simplicity of buffer overflow triggering via network packets means organizations should not rely on exploits remaining unavailable. Exposure is highest in organizations that allow untrusted network segments to reach TSA ports, such as guest networks or external-facing deployments.

Remediation

Apply the appropriate security patch for your PAN-OS version as provided by Palo Alto Networks. As an immediate mitigation, implement network segmentation to restrict Terminal Server Agent connectivity strictly to trusted internal IP addresses and subnets, following Palo Alto's published deployment best practices. Disable TSA if not actively required for user identification. Consider using firewall rules to limit access to TSA ports to known administrative and identity server source IPs only. Monitor TSA logs and network traffic for signs of exploitation attempts.

Patch guidance

Palo Alto Networks has released security fixes for affected PAN-OS versions. Verify the specific patch version applicable to your deployment via the official Palo Alto Networks Security Advisory and PAN-OS release notes. Prioritize patching instances where TSA is exposed to less-trusted network segments. After patching, validate that TSA connectivity remains restricted to trusted IPs and that user identification functionality is restored. Test in a staging environment first to confirm compatibility with your security policies and integrations.

Detection guidance

Monitor for network traffic to TSA service ports from unexpected or untrusted IP ranges. Look for malformed packets, buffer overflow indicators, or repeated connection attempts with abnormal payloads targeting TSA. Check PAN-OS system logs and User-ID Agent logs for crashes, service restarts, or error messages that may indicate exploitation attempts. Implement network-based detection rules that flag suspicious traffic patterns to TSA endpoints. Monitor memory and CPU utilization spikes on firewalls running TSA, as DoS attempts may cause observable resource exhaustion before service failure.

Why prioritize this

This vulnerability merits prompt attention due to its HIGH CVSS score (7.5), network-accessible attack vector, and lack of authentication barriers. The potential for both denial of service and code execution on a critical security appliance makes it a perimeter risk. However, organizations that follow Palo Alto's segmentation guidance can meaningfully reduce their exposure. Prioritize patching of TSA-enabled firewalls that face less-trusted network segments (edge, DMZ, cloud perimeters) before those in fully internal, segmented deployments. The absence from the KEV catalog suggests active exploitation may not yet be widespread, providing a window for orderly remediation before threat actors weaponize it at scale.

Risk score, explained

The CVSS 3.1 score of 7.5 reflects a network-accessible vulnerability with no authentication requirement and low attack complexity, resulting in HIGH severity and significant availability impact. The score does not assign confidentiality or integrity points in the base vector, but the potential for arbitrary code execution and the critical role of firewalls in network defense justify treating this as a high-priority issue. Risk is contextual: organizations with TSA isolated to trusted networks via proper segmentation face lower practical risk than those with broad exposure. The absence of active public exploitation does not reduce the severity, only the current threat likelihood.

Frequently asked questions

Does this affect Panorama appliances?

No. According to Palo Alto Networks, Panorama management servers are not impacted by this vulnerability. Only PAN-OS firewalls running the User-ID Terminal Server Agent component are affected.

What is the User-ID Terminal Server Agent, and do we need it?

TSA is a PAN-OS component that enables user identification and user-based firewall policies by collecting user logon information from Windows terminal servers and other identity sources. If your organization does not use PAN-OS user identification features, you may be able to disable TSA entirely, eliminating the attack surface. Review your security policies to determine necessity.

How much does network segmentation reduce our risk?

Significantly. Palo Alto Networks explicitly notes that restricting TSA connectivity to trusted internal IP addresses minimizes security risk. If you can ensure TSA is reachable only from your identity infrastructure and administrative networks (not from guest, cloud, or DMZ segments), you substantially lower the likelihood of successful exploitation by external or untrusted actors.

Should we wait for more information before patching?

No. While the vulnerability is not yet in CISA's KEV catalog, the combination of network access, no authentication, and potential for code execution on a critical appliance warrants prompt patching. As a precaution, apply the patch during a maintenance window after validating it in a lab environment with your specific configuration.

This analysis is provided for informational purposes and reflects the vulnerability details as of the publication date. Security risk is context-dependent and varies based on deployment architecture, network segmentation, and patch status. Organizations must verify affected versions, patch availability, and compatibility with their specific PAN-OS releases via official Palo Alto Networks advisories. This information does not constitute legal or compliance advice. Always test patches in non-production environments before deployment. SEC.co recommends consultation with Palo Alto Networks support for environment-specific guidance. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).