Executive brief
A vulnerability exists in the Terminal Server Agent component of Palo Alto Networks firewalls, which is used to identify users in multi-user environments. An attacker could exploit this to crash the security system or potentially take control of the device. This could lead to a total loss of network security controls and unauthorized access to sensitive corporate data.
Technical details
The vulnerability consists of multiple buffer overflows (CWE-787: Out-of-bounds Write) within the User-ID Terminal Server Agent (TSA) component of PAN-OS. An unauthenticated attacker can trigger these overflows by sending specially crafted network traffic to the TSA service. Successful exploitation can lead to a denial-of-service (DoS) or remote code execution (RCE) with high privileges. The risk is significantly elevated if the TSA service is exposed to the internet or untrusted networks. Patches are available for various PAN-OS branches including 10.2, 11.1, 11.2, and 12.1.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.4-h8, 12.1 < 12.1.7-h2, 12.1 < 12.1.8, 11.2 < 11.2.4-h20, 11.2 < 11.2.7-h18, 11.2 < 11.2.10-h12, 11.2 < 11.2.13, 11.1 < 11.1.4-h35, 11.1 < 11.1.6-h35, 11.1 < 11.1.7-h8, 11.1 < 11.1.10-h30, 11.1 < 11.1.13-h9, 11.1 < 11.1.16, 10.2 < 10.2.7-h36, 10.2 < 10.2.10-h39, 10.2 < 10.2.13-h23, 10.2 < 10.2.16-h9, 10.2 < 10.2.18-h8
- Palo Alto Networks Prisma Access 11.2.0 < 11.2.7-h18, 10.2.0 < 10.2.10-h39
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched