Palo Alto Networks disclosed and patched 13 vulnerabilities across its products, led by CVE-2026-0288, a high-severity flaw in PAN-OS that can let an unauthenticated attacker with network access trigger memory corruption through specially crafted traffic. The bug stems from multiple buffer overflows in the User-ID Terminal Server Agent (TSA) component and can lead to denial of service and potentially arbitrary code execution on affected firewalls. Palo Alto said the issue affects PAN-OS devices only when at least one TSA entry is configured, while Panorama and Cloud NGFW on AWS are not affected.
The company assigned the flaw a CVSS-B score of 9.2 for exposed deployments and said it has no evidence of active exploitation, but urged customers to patch immediately or restrict TSA access to trusted internal IP addresses as a mitigation. The broader advisory batch also addressed medium- and low-severity issues in PAN-OS and Prisma Access Agent, including vulnerabilities that could enable root command execution, unauthorized internal requests, authentication bypass, VPN interception via MitM, DLP policy bypass, privilege escalation, XSS-driven code execution, file deletion, and information disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks published advisories covering 13 vulnerabilities across PAN-OS and Prisma Access Agent, including medium- and low-severity issues such as root command execution, unauthorized internal requests, authentication bypass, VPN interception, DLP policy bypass, privilege escalation, XSS-driven code execution, file deletion, and information disclosure. The company said it was not aware of in-the-wild exploitation and urged customers to apply patches.
Palo Alto Networks disclosed CVE-2026-0288, a high-severity PAN-OS vulnerability caused by multiple buffer overflows in the User-ID Terminal Server Agent component that can lead to denial of service and potentially arbitrary code execution via crafted network traffic. The company said the issue affects PAN-OS only when at least one Terminal Server Agent entry is configured, noted no known active exploitation, and urged customers to patch or restrict TSA access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.