CVE-2026-0228: Palo Alto Networks Cloud Ngfw
Low severity, CVSS 1.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
Affected products
- Palo Alto Networks Cloud Ngfw
- Palo Alto Networks PAN-OS: from 11.2.0, before 11.2.8 (fixed in 11.2.8); from 11.1.0, before 11.1.11 (fixed in 11.1.11); from 10.2.0, before 10.2.17 (fixed in 10.2.17)
- Palo Alto Networks Prisma Access: from 10.2.0, before 10.2.10-h28 (fixed in 10.2.10-h28)
Published 2026-02-11. Last modified 2026-06-17.