Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · juniper

juniper

· 23 Critical

Total CVEs

1,080

Critical

23

Products

421

Search All CVEs →

1,080

Products (421)

junos771 CVEsjunos os evolved240 CVEssrx5600147 CVEssrx5800147 CVEssrx5400133 CVEssrx1500124 CVEssrx4100120 CVEssrx4200119 CVEssrx300119 CVEssrx340114 CVEssrx345114 CVEssrx320113 CVEssrx4600113 CVEssrx550109 CVEsmx48095 CVEsmx96095 CVEssrx140094 CVEssrx340094 CVEssrx360094 CVEssrx22094 CVEssrx11094 CVEssrx10093 CVEssrx21093 CVEsmx24093 CVEssrx65093 CVEssrx24092 CVEsmx201087 CVEssrx38087 CVEsmx202085 CVEsmx200884 CVEsmx20480 CVEsjunos space78 CVEsmx1000872 CVEsqfx520065 CVEsex460064 CVEsqfx511063 CVEsmx10460 CVEsmx1000360 CVEsmx4059 CVEsmx1059 CVEsmx8059 CVEssrx550 hm58 CVEsmx15058 CVEsmx558 CVEsex430056 CVEsex230056 CVEsex340056 CVEssrx400054 CVEssrx500052 CVEssrx550m50 CVEsqfx510049 CVEsmx1000048 CVEssrx240h248 CVEsex465047 CVEsmx1001646 CVEsqfx512045 CVEsqfx521044 CVEssrx470038 CVEssrx160037 CVEssrx230037 CVEssrx430037 CVEsex2300-c36 CVEsqfx1000234 CVEsqfx1000834 CVEsqfx1001634 CVEssrx240m34 CVEsex920033 CVEsqfx522033 CVEsqfx513032 CVEsmx1000431 CVEsmx30430 CVEsnfx25029 CVEsptx1000828 CVEssrx412026 CVEsex440025 CVEsex420025 CVEsnfx15025 CVEsptx1000325 CVEsvsrx24 CVEsptx1001624 CVEsptx1000423 CVEsex455022 CVEsex330022 CVEsex925022 CVEsqfx350021 CVEsex920820 CVEsex920420 CVEsptx100020 CVEsex220020 CVEsex320019 CVEsqfx1000019 CVEsnorthstar controller19 CVEsptx10001-36mr19 CVEsex921419 CVEsex450018 CVEsqfx360018 CVEsptx500018 CVEsex2200-c18 CVEsex620017 CVEsptx300017 CVEscsrx17 CVEsex4300-24p-s16 CVEsscreenos16 CVEsex4300-24p16 CVEsex4300-32f16 CVEsex4300-32f-s16 CVEsex4300-48mp16 CVEsex4300-48mp-s16 CVEsex4300-48p16 CVEsex4300-48p-s16 CVEsex4300-48t16 CVEsex4300-48t-afi16 CVEsex4300-48t-dc16 CVEsex4300-48t-dc-afi16 CVEsex4300-48t-s16 CVEsex4300-mp16 CVEsex4600-vc16 CVEsptx1000216 CVEsex2300m16 CVEsex4300-24t16 CVEsex4300-24t-s16 CVEsex4300-32f-dc16 CVEsex925315 CVEsqfx570015 CVEsex925115 CVEsex4300m15 CVEsex820014 CVEsex820814 CVEsex821614 CVEsex4550-vc14 CVEsex4550\/vc14 CVEsex621014 CVEsex4300-48tafi13 CVEsex3300-vc13 CVEsex410013 CVEsex8200-vc13 CVEsatp70013 CVEsatp40013 CVEsex4300-vc13 CVEsex4300-48tdc-afi13 CVEsex4300-48tdc13 CVEsex4200-vc13 CVEsex4500-vc13 CVEsex2200-vc12 CVEsnfx35011 CVEsacx750911 CVEsqfx5200-32c11 CVEsqfx5200-48y11 CVEsadvanced threat prevention11 CVEsex4100-f11 CVEsqfx5210-64c11 CVEsqfx524010 CVEsqfx5100-96s10 CVEsex2300-24mp10 CVEsex2300-24p10 CVEsex2300-24t10 CVEsex2300-48mp10 CVEsex2300-48p10 CVEsex2300-48t10 CVEsqfx524110 CVEsqfx5230-64cd10 CVEsmx10 CVEsptx100019 CVEsacx70249 CVEsptx10002-60c9 CVEsacx7024x9 CVEsnetscreen screenos9 CVEsvmx8 CVEsacx54488 CVEsqfx10002-60c8 CVEsqfx10002-32q7 CVEsacx7107 CVEsacx71007 CVEsacx70207 CVEsacx73007 CVEsqfx10002-72q7 CVEsptx1000-72q7 CVEsptx100007 CVEsptx1000167 CVEsptx10003 160c7 CVEsptx10003 80c7 CVEsptx10003 81cd7 CVEsex4100-h7 CVEsqfx3000-m7 CVEscontrail service orchestration7 CVEsqfx3000-g7 CVEsex rps6 CVEsive os6 CVEsex40006 CVEsjunos space ja1500 appliance6 CVEsacx40006 CVEslibslax5 CVEsacx22005 CVEsqfx3600-i5 CVEsacx50965 CVEsacx11005 CVEsjunos pulse secure access service5 CVEsacx10005 CVEsacx21005 CVEsqfx3008-i5 CVEsacx5005 CVEsqfx31005 CVEsparagon active assurance control center5 CVEsptx10002-36qdd5 CVEsacx50485 CVEsmpc115 CVEsqfk52004 CVEsacx50004 CVEsex redundant power system4 CVEsex9200-15c4 CVEsjunos space virtual appliance4 CVEssession and resource control4 CVEssecure access 20004 CVEslc96004 CVEsnetscreen-54004 CVEsmpc10e-10c4 CVEsmpc10e-15c4 CVEsacx7100-32c4 CVEsacx7100-48l4 CVEsqfk57004 CVEsqfk52304 CVEsqfk52204 CVEsqfk52104 CVEsmx-spc34 CVEsacx20004 CVEsqfk51304 CVEsqfk51204 CVEsqfk51104 CVEsmx3014 CVEsnetscreen-52004 CVEsex4400 multigigabit3 CVEsjunose3 CVEsex8200\/vc \(xre\)3 CVEsjunos pulse access control service3 CVEsctpview3 CVEsfips secure access 40003 CVEsfips secure access 45003 CVEsfips secure access 60003 CVEsacx63603 CVEsfips secure access 65003 CVEsmag2600 gateway3 CVEspulse connect secure3 CVEsex4100 multigigabit3 CVEsex2200\/vc3 CVEsex4300 multigigabit3 CVEsex4400-24x3 CVEssecure access 25003 CVEssecure access 45003 CVEssecure access 7003 CVEsacx58003 CVEsqfx10k3 CVEst6403 CVEst40003 CVEsex2300 multigigabit3 CVEst3203 CVEsex3300\/vc3 CVEsmist cloud ui3 CVEsmag6611 gateway3 CVEst16003 CVEsmag6610 gateway3 CVEsmag4610 gateway3 CVEsqfx102 CVEs2x100ge \+ 4x10ge mpc5e2 CVEs2x100ge \+ 4x10ge mpc5eq2 CVEs2x100ge \+ 8x10ge mpc4e2 CVEs32x10ge mpc4e2 CVEs6x40ge \+ 24x10ge mpc5e2 CVEs6x40ge \+ 24x10ge mpc5eq2 CVEsacx54002 CVEsacx5448-d2 CVEsacx5448-m2 CVEsacx63002 CVEsacx73482 CVEsappformix2 CVEscontrail2 CVEsdx2 CVEsfips infranet controller 65002 CVEsgfx36002 CVEsidentity management service2 CVEsidp2502 CVEsidp752 CVEsidp8002 CVEsidp82002 CVEsinfranet controller 40002 CVEsinfranet controller 45002 CVEsinfranet controller 60002 CVEsinfranet controller 65002 CVEsjunos e2 CVEsjunos space ja2500 appliance2 CVEsmpc12 CVEsmpc1 q2 CVEsmpc1e2 CVEsmpc1e q2 CVEsmpc22 CVEsmpc2 eq2 CVEsmpc2 q2 CVEsmpc2e2 CVEsmpc2e eq2 CVEsmpc2e ng2 CVEsmpc2e ng q2 CVEsmpc2e p2 CVEsmpc2e q2 CVEsmpc3e2 CVEsmpc3e-3d-ng2 CVEsmpc3e-3d-ng-q2 CVEsmpc6e2 CVEsmpc7e-10g2 CVEsmpc7e-mrate2 CVEsmpc8e2 CVEsmpc9e2 CVEsms-mic2 CVEsms-mpc2 CVEsnetscreen-5gt2 CVEsnetscreen-idp2 CVEsnetscreen-idp 102 CVEsnetscreen-idp 1002 CVEsnetscreen-idp 10002 CVEsnetscreen-idp 5002 CVEsnetscreen-security manager 20042 CVEsnfx2 CVEsnfx series2 CVEsnsm30002 CVEsnsmexpress2 CVEsocx11002 CVEsptx120082 CVEssecure access2 CVEssecure access 40002 CVEssecure access 60002 CVEssecure access 65002 CVEssmartpass2 CVEsspace security director2 CVEsxre2002 CVEsodyssey access client1 CVEsnetworks mobility system software1 CVEsnetwork and security manager software1 CVEsnetscreen remote vpn client1 CVEsnetscreen remote security client1 CVEsmx304-lmic161 CVEsmpc101 CVEsmobile system software1 CVEsmag pcs3601 CVEsm7i1 CVEsm3201 CVEsm1201 CVEsm10i1 CVEsln26001 CVEsln10001 CVEsringmaster1 CVEsrouter m101 CVEsrouter m161 CVEsrouter m201 CVEsrouter m401 CVEsrouter m51 CVEssbr carrier1 CVEslc48001 CVEsadvanced threat prevention firmware1 CVEslc4801 CVEslc21011 CVEstrusted platform module firmware1 CVEsjunose t1 CVEsunified access control software1 CVEsvirtual advanced threat protection1 CVEsjunose m1 CVEssecure access virtual appliance1 CVEssecurity director1 CVEssecurity director policy enforcer1 CVEssecurity threat response manager1 CVEsservice insight1 CVEsservice now1 CVEsjunose j1 CVEsacx73321 CVEs128 technology session smart router firmware1 CVEssr46001 CVEssrc pe1 CVEssrx1 CVEsjunose e1 CVEsjunos t1 CVEsjunos pulse client1 CVEsjunos m1 CVEsjunos j1 CVEsjunos containerized routing protocol daemon1 CVEsjunipersetup control1 CVEsjuniper installer service client1 CVEsjsnapy1 CVEsjsa78001 CVEsjsa75001 CVEsjsa58001 CVEsjsa55001 CVEsjsa38001 CVEsjsa35001 CVEsjsa15001 CVEsjrr2001 CVEsjnos1 CVEsjdpi-decoder engine1 CVEsjatp1 CVEsj-web1 CVEsidp1 CVEshttp service1 CVEsex4650-48y1 CVEsex4300mp1 CVEsex4000-48t1 CVEsex4000-48p1 CVEsex4000-48mp1 CVEsctp20561 CVEsctp20241 CVEsctp20081 CVEsctp1501 CVEssrx5k-spc31 CVEscontrail networking1 CVEssrx series1 CVEssteel-belted radius carrier1 CVEscontrail cloud1 CVEsappid service sigpack1 CVEsadvanced threat protection1 CVEs128 technology session smart router1 CVEsqfabric1 CVEspcs65001 CVEspcs60001 CVEsparagon automation1 CVEsparagon active assurance test agent1 CVEsparagon active assurance1 CVEs

Recent Vulnerabilities

View all 1,080
CVE-2026-33797HIGH 7.4

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS). An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS: * 25.2 versions before 25.2R2 This issue does not affect Junos OS versions before 25.2R1. This issue affects Junos OS Evolved: * 25.2-EVO versions before 25.2R2-EVO This issue does not affect Junos OS Evolved versions before 25.2R1-EVO. eBGP and iBGP are affected. IPv4 and IPv6 are affected.

CVE-2026-33793HIGH 7.8

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation.  This issue affects Junos OS:  * All versions before 22.4R3-S7,  * from 23.2 before 23.2R2-S4,  * from 23.4 before 23.4R2-S6, * from 24.2 before 24.2R1-S2, 24.2R2,  * from 24.4 before 24.4R1-S2, 24.4R2;  Junos OS Evolved:  * All versions before 22.4R3-S7-EVO,  * from 23.2 before 23.2R2-S4-EVO,  * from 23.4 before 23.4R2-S6-EVO, * from 24.2 before 24.2R2-EVO,  * from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.

CVE-2026-33791MEDIUM 6.7

An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system. Certain 'set system' commands, when executed with crafted arguments, are not properly sanitized, allowing for arbitrary shell injection. These shell commands are executed as root, potentially allowing for complete control of the vulnerable system. This issue affects: Junos OS:  * all versions before 22.4R3-S8,  * from 23.2 before 23.2R2-S5,  * from 23.4 before 23.4R2-S7,  * from 24.2 before 24.2R2-S2,  * from 24.4 before 24.4R2,  * from 25.2 before 25.2R2;  Junos OS Evolved:  * all versions before 22.4R3-S8-EVO,  * from 23.2 before 23.2R2-S5-EVO,  * from 23.4 before 23.4R2-S7-EVO,  * from 24.2 before 24.2R2-S2-EVO,  * from 24.4 before 24.4R2-EVO,  * from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.

CVE-2026-33790HIGH 7.5

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly crash the srxpfe process and sustain the Denial of Service (DoS) condition. During NAT64 translation, receipt of a specific, malformed ICMPv6 packet destined to the device will cause the srxpfe process to crash and restart. This issue cannot be triggered using IPv4 nor other IPv6 traffic. This issue affects Junos OS on SRX Series: * all versions before 21.2R3-S10, * all versions of 21.3, * from 21.4 before 21.4R3-S12, * all versions of 22.1, * from 22.2 before 22.2R3-S8, * all versions of 22.4, * from 22.4 before 22.4R3-S9, * from 23.2 before 23.2R2-S6, * from 23.4 before 23.4R2-S7, * from 24.2 before 24.2R2-S3, * from 24.4 before 24.4R2-S3, * from 25.2 before 25.2R1-S2, 25.2R2.

CVE-2026-33787MEDIUM 5.5

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600:  * 23.2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7 * 24.2 versions before 24.2R2-S2, * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R1-S1, 25.2R2.

CVE-2026-33786MEDIUM 5.5

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1600, SRX2300 and SRX4300: * 24.4 versions before 24.4R1-S3, 24.4R2. This issue does not affect Junos OS versions before 24.4R1.

CVE-2026-33785HIGH 8.8

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These commands are only meant to be executed by high privileged or users designated for Juniper Device Manager (JDM) / Connected Security Distributed Services (CSDS) operations as they will impact all aspects of the devices managed via the respective MX. This issue affects Junos OS on MX Series: * 24.4 releases before 24.4R2-S3,  * 25.2 releases before 25.2R2. This issue does not affect Junos OS releases before 24.4.

CVE-2026-33783MEDIUM 6.5

A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privileges to cause a complete Denial of Service (DoS). If colored SRTE policy tunnels are provisioned via PCEP, and gRPC is used to monitor traffic in these tunnels, evo-aftmand crashes and doesn't restart which leads to a complete and persistent service impact. The system has to be manually restarted to recover. The issue is seen only when the Originator ASN field in PCEP contains a value larger than 65,535 (32-bit ASN). The issue is not reproducible when SRTE policy tunnels are statically configured. This issue affects Junos OS Evolved on PTX Series:  * all versions before 22.4R3-S9-EVO, * 23.2 versions before 23.2R2-S6-EVO, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S4-EVO, * 24.4 versions before 24.4R2-S2-EVO, * 25.2 versions before 25.2R1-S2-EVO, 25.2R2-EVO.

CVE-2026-33782MEDIUM 6.5

A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS). In a DHCPv6 over PPPoE, or DHCPv6 over VLAN with Active lease query or Bulk lease query scenario, every subscriber logout will leak a small amount of memory. When all available memory has been exhausted, jdhcpd will crash and restart which causes a complete service impact until the process has recovered. The memory usage of jdhcpd can be monitored with: user@host> show system processes extensive | match jdhcpd This issue affects Junos OS: * all versions before 22.4R3-S1, * 23.2 versions before 23.2R2, * 23.4 versions before 23.4R2.

CVE-2026-33781MEDIUM 6.5

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS). On EX4k, and QFX5k platforms configured as service-provider edge devices, if L2PT is enabled on the UNI and VSTP is enabled on NNI in VXLAN scenarios, receiving VSTP BPDUs on UNI leads to packet buffer allocation failures, resulting in the device to not pass traffic anymore until it is manually recovered with a restart.This issue affects Junos OS: * 24.4 releases before 24.4R2, * 25.2 releases before 25.2R1-S1, 25.2R2. This issue does not affect Junos OS releases before 24.4R1.

CVE-2026-33780MEDIUM 6.5

A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS). In an EVPN-MPLS scenario, routes learned from remote multi-homed Provider Edge (PE) devices are programmed as ESI routes. Due to a logic issue in the l2ald memory management, memory allocated for these routes is not released when there is churn for these routes. As a result, memory leaks in the l2ald process which will ultimately lead to a crash and restart of l2ald. Use the following command to monitor the memory consumption by l2ald: user@device> show system process extensive | match "PID|l2ald" This issue affects: Junos OS: * all versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2; Junos OS Evolved: * all versions before 22.4R3-S5-EVO, * 23.2 versions before 23.2R2-S3-EVO, * 23.4 versions before 23.4R2-S4-EVO, * 24.2 versions before 24.2R2-EVO.

CVE-2026-33779MEDIUM 6.5

An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially modify it. When an SRX device is provisioned to connect to Security Director (SD) cloud, it doesn't perform sufficient verification of the received server certificate. This allows a PITM to intercept the communication between the SRX and SD cloud and access credentials and other sensitive information. This issue affects Junos OS: * all versions before 22.4R3-S9, * 23.2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R1-S2, 25.2R2.

CVE-2026-33778HIGH 7.5

An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). If an affected device receives a specifically malformed first ISAKMP packet from the initiator, the kmd/iked process will crash and restart, which momentarily prevents new security associations (SAs) for from being established. Repeated exploitation of this vulnerability causes a complete inability to establish new VPN connections. This issue affects Junos OS on SRX Series and MX Series: * all versions before 22.4R3-S9, * 23.2 version before 23.2R2-S6, * 23.4 version before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R1-S2, 25.2R2.

CVE-2026-33776MEDIUM 5.5

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information. A local user with low privileges can execute the CLI command 'show mgd' with specific arguments which will expose sensitive information. This issue affects Junos OS: * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S1, * 25.2 version before 25.2R1-S2, 25.2R2; Junos OS Evolved: * all versions before 23.2R2-S6-EVO, * 23.4 version before 23.4R2-S6-EVO, * 24.2 version before 24.2R2-S4-EVO, * 24.4 versions before 24.4R2-S1-EVO, * 25.2 versions before 25.2R2-EVO.

CVE-2026-33775MEDIUM 6.5

A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If the authentication packet-type option is configured and a received packet does not match that packet type, the memory leak occurs. When all memory available to bbe-smgd has been consumed, no new subscribers will be able to login. The memory utilization of bbe-smgd can be monitored with the following show command: user@host> show system processes extensive | match bbe-smgd The below log message can be observed when this limit has been reached: bbesmgd[<PID>]: %DAEMON-3-SMD_DPROF_RSMON_ERROR: Resource unavailability, Reason: Daemon Heap Memory exhaustion This issue affects Junos OS on MX Series: * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S5, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2R2-S2, * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R2.

CVE-2026-33773MEDIUM 5.8

An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks. When the same family inet or inet6 filter is applied on an IRB interface and on a physical interface as egress filter on EX4100, EX4400, EX4650 and QFX5120 devices, only one of the two filters will be applied, which can lead to traffic being sent out one of these interfaces which should have been blocked. This issue affects Junos OS on EX Series and QFX Series: * 23.4 version 23.4R2-S6, * 24.2 version 24.2R2-S3. No other Junos OS versions are affected.

CVE-2026-21919MEDIUM 6.5

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane. When NETCONF sessions are quickly established and disconnected, a locking issue causes mgd processes to hang in an unusable state. When the maximum number of mgd processes has been reached, no new logins are possible. This leads to the inability to manage the device and requires a power-cycle to recover. This issue can be monitored by checking for mgd processes in lockf state in the output of 'show system processes extensive': user@host> show system processes extensive | match mgd <pid> root       20   0 501M 4640K lockf   1 0:01 0.00% mgd If the system still can be accessed (either via the CLI or as root, which might still be possible as last resort as this won't invoke mgd), mgd processes in this state can be killed with 'request system process terminate <PID>' from the CLI or with 'kill -9 <PID>' from the shell.  This issue affects: Junos OS: * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R1-S3, 24.4R2; This issue does not affect Junos OS versions before 23.4R1; Junos OS Evolved: * 23.4 versions before 23.4R2-S5-EVO, * 24.2 versions before 24.2R2-S1-EVO, * 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO. This issue does not affect Junos OS Evolved versions before 23.4R1-EVO;

CVE-2026-21916HIGH 7.3

A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system. When after a user has performed a specific 'file link ...' CLI operation, another user commits (unrelated configuration changes), the first user can login as root. This issue affects Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R2. This issue does not affect versions 25.4R1 or later.

CVE-2025-59969MEDIUM 6.5

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).An attacker sending crafted multicast packets will cause line cards running evo-aftmand/evo-pfemand to crash and restart or non-line card devices to crash and restart. Continued receipt and processing of these packets will sustain the Denial of Service (DoS) condition. This issue affects Junos OS Evolved PTX Series: * All versions before 22.4R3-S8-EVO, * from 23.2 before 23.2R2-S5-EVO, * from 23.4 before 23.4R2-EVO, * from 24.2 before 24.2R2-EVO, * from 24.4 before 24.4R2-EVO. This issue affects Junos OS Evolved on QFX5000 Series: * 22.2-EVO version before 22.2R3-S7-EVO, * 22.4-EVO version before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S5-EVO, * 24.2-EVO versions before 24.2R2-S1-EVO, * 24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO. This issue does not affect Junos OS Evolved on QFX5000 Series versions before: 21.2R2-S1-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO, and 22.1R1-EVO.

CVE-2026-21902CRITICAL 9.8

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.

CVE-2026-21921MEDIUM 6.5

A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS). When telemetry collectors are frequently subscribing and unsubscribing to sensors continuously over a long period of time, telemetry-capable processes like chassisd, rpd or mib2d will crash and restart, which - depending on the process - can cause a complete outage until the system has recovered. This issue affects:  Junos OS:  * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S5, * 23.4 versions before 23.4R2; Junos OS Evolved: * all versions before 22.4R3-S8-EVO, * 23.2 versions before 23.2R2-S5-EVO, * 23.4 versions before 23.4R2-EVO.

CVE-2026-21920HIGH 7.5

An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd will crash and restart, which causes a service interruption until the process has recovered. This issue affects Junos OS on SRX Series: * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R2. This issue does not affect Junos OS versions before 23.4R1.

CVE-2026-21918HIGH 7.5

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of packets is encountered a double free happens. This causes flowd to crash and the respective FPC to restart. This issue affects Junos OS on SRX and MX Series: * all versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2.

CVE-2026-21917HIGH 7.5

An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX device configured for UTM Web-Filtering receives a specifically malformed SSL packet, this will cause an FPC crash and restart. This issue affects Junos OS on SRX Series: * 23.2 versions from 23.2R2-S2 before 23.2R2-S5,  * 23.4 versions from 23.4R2-S1 before 23.4R2-S5, * 24.2 versions before 24.2R2-S2, * 24.4 versions before 24.4R1-S3, 24.4R2. Earlier versions of Junos are also affected, but no fix is available.

CVE-2026-21914HIGH 7.5

An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos). If an SRX Series device receives a specifically malformed GPRS Tunnelling Protocol (GTP) Modify Bearer Request message, a lock is acquired and never released. This results in other threads not being able to acquire a lock themselves, causing a watchdog timeout leading to FPC crash and restart. This issue leads to a complete traffic outage until the device has automatically recovered. This issue affects Junos OS on SRX Series: * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S5, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R1-S1, 25.2R2.