Palo Alto Networks patches 13 vulnerabilities in PAN-OS and Prisma Access Agent, including high-urgency firewall flaw CVE-2026-0288

Palo Alto Networks released fixes for 13 security flaws affecting its firewall and remote-access products. The most serious issue, CVE-2026-0288, is a high-severity PAN-OS buffer-overflow flaw that can let an unauthenticated attacker with network access crash a firewall and potentially run code via specially crafted traffic against the User-ID Terminal Server Agent feature. Other patched flaws affect PAN-OS and Prisma Access Agent, including command injection, server-side request forgery (making the product send unauthorized internal requests), authentication bypass, information disclosure, privilege escalation, and VPN traffic interception or data loss prevention bypass.
Why it matters: Organizations using Palo Alto firewalls or Prisma Access Agent should review the advisories and patch promptly, especially if exposed management or TSA-related access is broader than best practice. Even though Palo Alto says it has not seen active exploitation, firewall and VPN flaws are routinely targeted once patches are available.

Sources

Palo Alto Networks Patches 13 Vulnerabilities
Eduard Kovacs 2026.07.09 100% relevant
This article appears to be the first item here establishing the specific July 9, 2026 Palo Alto Networks advisory set for 13 vulnerabilities, centered on PAN-OS CVE-2026-0288 and related PAN-OS and Prisma Access Agent fixes.
← Back to all stories