Home
LOW: 1.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:AmberDefault status
unaffected
All (custom)
unaffected
Default status
unaffected
12.1.0 (custom) before 11.2.8
unaffected
11.2.0 (custom) before 11.2.8
affected
11.1.0 (custom) before 11.1.11
affected
10.2.0 (custom) before 10.2.17
affected
Default status
unaffected
10.2.0 (custom) before 10.2.10-h28
affected
Description
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
Problem types
CWE-295 Improper Certificate Validation
Product status
All (custom)
12.1.0 (custom) before 11.2.8
11.2.0 (custom) before 11.2.8
11.1.0 (custom) before 11.1.11
10.2.0 (custom) before 10.2.17
10.2.0 (custom) before 10.2.10-h28
Timeline
| 2026-02-11: | Initial Publication |
Credits
Paolo Nero of Wellcomm Engineering
References
security.paloaltonetworks.com/CVE-2026-0228