Back to search
CVE-2026-0228
Published: Feb 11, 2026
Modified: Feb 11, 2026
PUBLISHED
Description
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Cloud NGFW | unaffected All |
Palo Alto Networks | PAN-OS | unaffected 12.1.0 - < 11.2.8affected 11.2.0 - < 11.2.8affected 11.1.0 - < 11.1.11affected 10.2.0 - < 10.2.17 |
Palo Alto Networks | Prisma Access | affected 10.2.0 - < 10.2.10-h28 |
Weaknesses (CWE)
References
https://security.paloaltonetworks.com/CVE-2026-0228
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now