EN·DE

Palo Alto Networks Patches Critical Buffer Overflow in PAN-OS and Prisma Products

Palo Alto Networks released security updates on July 8, 2026, addressing a buffer overflow vulnerability in PAN-OS and Prisma products, affecting dozens of versions.

This article was drafted with AI assistance from multiple sources and was reviewed and approved by a human editor before publication.

Palo Alto Networks issued a security advisory on July 8, 2026, to address a buffer overflow vulnerability in its PAN-OS and Prisma products. The flaw, tracked as CVE-2026-0288 and documented in PAN-SA-2026-0010, resides in the User-ID Terminal Server Agent and could allow an attacker to execute arbitrary code or cause a denial-of-service condition.

The advisory covers a wide range of PAN-OS versions. For example, PAN-OS 12.1 is affected in versions before 12.1.4-h8, 12.1.7-h2, and 12.1.8. Similarly, PAN-OS 11.2 has multiple vulnerable builds such as those prior to 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, and 11.2.13.

The vulnerability also impacts Prisma Access deployments: versions 11.20.0 prior to 11.2.7-h18 and versions 10.2.0 prior to 10.2.10-h39 are affected. Additionally, Prisma Browser versions before 149.10.3.53 are vulnerable.

The Canadian Cyber Centre has urged administrators to review the advisories, apply mitigations, and install the necessary updates promptly. No reports of active exploitation have been confirmed at the time of publication.

Sources

  1. Canadian Centre for Cyber Security Alerts – Palo Alto Networks security advisory (AV26-674)