Juniper Networks MX / Routers Vulnerabilities & Security Advisories
24 advisories tracked · Juniper SIRT (JSA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Juniper Networks advisory that VulniPulse classified as MX / Routers, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 7 high, 16 medium.
Android app · Google Play
Monitor Juniper CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Juniper SIRT (JSA) via NVD
Juniper's advisory portal (kb.juniper.net) is a login-walled Salesforce app, so VulniPulse ingests Juniper SIRT (JSA) advisories from NVD, filtered to Juniper's own CNA (sirt@juniper.net) — official, machine-readable data with the affected Junos releases in each description. Junos on SRX/MX/EX/QFX and Junos Space are the common targets.
Latest Juniper MX / Routers advisories
High [CVE-2026-21905] Junos: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper…
A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC. This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue. - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S6, Affected products named by the advisory: MX; EX.
Medium [CVE-2026-21912] Junos: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of…
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged attacker executing the 'show system firmware' CLI command to cause an LC480 or LC2101 line card to reset. On MX10k Series systems with LC480 or LC2101 line cards, repeated execution of the 'show system firmware' CLI command can cause the line card to crash and restart. Additionally, some time after the line card crashes, chassisd may also crash and restart, generating a core dump. This issue affects Junos OS on MX10k Series: - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S9, - from 23.2 before 23.2R2-S2, - from 23.4 before 23.4R2-S3, Affected products named by the advisory: MX; EX.
Medium [CVE-2026-0203] Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS). When an ICMP packet is received with a specifically malformed IP header value, the FPC receiving the packet crashes and restarts. Due to the specific type of malformed packet, adjacent upstream routers would not forward the packet, limiting the attack surface to adjacent networks. This issue only affects ICMPv4. ICMPv6 is not vulnerable to this issue. This issue does not affect AFT-based line cards such as the MPC10, MPC11, LC4800, LC9600, and MX304. This issue affects Junos OS: - all versions before 21.2R3-S9, - from 21.4 before 21.4R3-S10, - from 22.3 before 22.3R3-S4, - from 23.2 before 23.2R2-S3, - from 23.4 before 23.4R2-S3, Affected products named by the advisory: MX; EX.
Medium [CVE-2025-60007] NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series
A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). When a user executes the 'show chassis' command with specifically crafted options, chassisd will crash and restart. Due to this all components but the Routing Engine (RE) in the chassis are reinitialized, which leads to a complete service outage, which the system automatically recovers from. This issue affects: Junos OS on MX, SRX and EX Series, except MX10000 Series and MX304: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5, - 23.4 versions before 23.4R2-S6, Affected products named by the advisory: MX; EX.