Palo Alto patches 13 flaws, fixes PAN-OS buffer overflow
Palo Alto Networks released patches for 13 product vulnerabilities, including high-severity PAN-OS buffer overflows (CVE-2026-0288) that can cause DoS and potential code execution; updates also fix 500+ Chromium bugs in Prisma.
Palo Alto Networks on Wednesday published patches addressing 13 product-specific vulnerabilities. The most severe is CVE-2026-0288, a set of buffer overflow flaws in PAN-OS that received a highest urgency rating. An unauthenticated attacker with network access to a vulnerable firewall could trigger a denial-of-service condition and, in some cases, execute arbitrary code by sending specially crafted network traffic. The company noted the risk is reduced when access to the User-ID Terminal Server Agent (TSA) is limited to trusted internal IP addresses.
Seven of the newly disclosed flaws carry medium severity ratings. Five affect PAN-OS and can be exploited to cause service disruption, run operating-system commands as root, make unauthorized requests from the firewall to internal services, expose information, or bypass authentication. Palo Alto Networks reported that higher-impact exploitation of some of these issues requires an attacker to already have administrative credentials on the device.
The remaining medium-severity vulnerabilities impact the Prisma Access Agent. These can be used in man-in-the-middle scenarios to intercept VPN traffic and to bypass data-loss prevention policy enforcement.
Five additional issues were rated low severity, though some have moderate urgency. They include weaknesses that could allow privilege escalation, cross-site scripting that can lead to code execution, firewall policy bypass, file deletion, and information disclosure. The company said it is not aware of any active exploitation of the newly patched vulnerabilities.
The advisories also cover more than 500 Chromium vulnerabilities recently fixed by Google that affect the Prisma browser, which is built on Chromium.
Palo Alto attributed several findings to external researchers and reported an increase in internal discovery of flaws driven by its use of artificial intelligence tools. The company advised customers to apply the available updates and follow recommended configuration steps, including restricting TSA access to trusted internal addresses.
PAN-OS is the operating system that runs Palo Alto Networks’ next-generation firewalls. Prisma is a suite of secure access and browsing products that includes a Chromium-based browser. The vendor’s advisories include technical details and mitigation steps; organizations operating Palo Alto equipment should review the notices and install the patches.








