PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Plan PatchCVSS 9.2CVE-2026-0288Jul 8, 2026
Palo Alto NetworksTransportation
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS allow an unauthenticated attacker with network access to cause a denial of service condition or potentially execute arbitrary code by sending specially crafted network traffic.
What this means
What could happen
An attacker who can reach your firewall's User-ID Terminal Server Agent could crash the service, causing loss of user identification data and potentially interrupting network operations, or could execute arbitrary code on the firewall.
Who's at risk
Palo Alto Networks firewall administrators, especially those using PAN-OS in transportation, utilities, or any critical infrastructure. Prisma Access users are also affected. Cloud NGFW deployments on AWS and Azure cannot be patched and have no mitigation path.
How it could be exploited
An attacker sends specially crafted network packets to the User-ID Terminal Server Agent port on a PAN-OS firewall or Prisma Access instance. The vulnerable component fails to validate the packet length, causing a buffer overflow that either crashes the service or allows code execution.
Prerequisites
- Network access to the User-ID Terminal Server Agent port on the firewall
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects network security infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (9)
7 with fix2 pending
ProductAffected VersionsFix Status
Cloud NGFWNone on AWSNo fix yet
Cloud NGFWNone on AzureNo fix yet
PAN-OSBelow 12.1.4-h812.1.4-h8+
PAN-OSBelow 12.1.7-h212.1.7-h2+
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.4-h2011.2.4-h20+
Prisma AccessBelow 11.2.7-h1811.2.7-h18+
Prisma AccessBelow 11.2.10-h1211.2.10-h12+
Remediation & Mitigation
0/4
Do now
0/2Cloud NGFW
HARDENINGFor Cloud NGFW deployments on AWS and Azure with no available patch, implement network segmentation to restrict access to the User-ID Terminal Server Agent from untrusted networks
All products
WORKAROUNDRestrict User-ID Terminal Server Agent connectivity to only trusted internal IP addresses using firewall access controls
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.4-h8 or later (for 12.1.4 branch), 12.1.7-h2 or later (for 12.1.7 branch), or 12.1.8 or later (for 12.1.8 branch)
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.4-h20 or later (for 11.2.4 branch), 11.2.7-h18 or later (for 11.2.7 branch), 11.2.10-h12 or later (for 11.2.10 branch), or 11.2.13 or later (for 11.2.13 branch)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e597d655-46a9-4a9b-9cbb-da2ce02c41c5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.