Skip to content
VulniPulse

Juniper Networks Switches Vulnerabilities & Security Advisories

28 advisories tracked · Juniper SIRT (JSA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Juniper Networks advisory that VulniPulse classified as Switches, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 8 high, 19 medium.

Android app · Google Play

Monitor Juniper CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Juniper SIRT (JSA) via NVD

Juniper's advisory portal (kb.juniper.net) is a login-walled Salesforce app, so VulniPulse ingests Juniper SIRT (JSA) advisories from NVD, filtered to Juniper's own CNA (sirt@juniper.net) — official, machine-readable data with the affected Junos releases in each description. Junos on SRX/MX/EX/QFX and Junos Space are the common targets.

Latest Juniper Switches advisories

Medium6.5Juniper

Medium [CVE-2026-57032] Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS)

An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS). If an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX4400 via gRPC, this causes the FPC to crash. This leads to a complete service outage until the module has automatically restarted. The following log message can be seen when this issue happens: agentd[]: AGENTD_RESOURCE_NOT_FOUND: No resource name found for This issue affects Junos OS on - all versions before 23.2R2-S7, - 23.4 versions before 23.4R2-S8, Affected products named by the advisory: EX. Affected products named by the advisory: EX.

CVE-2026-57032
SwitchesJunosEX / QFX SwitchesEX2300
Jul 9, 2026
Medium5.3Juniper

Medium [CVE-2026-57029] Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS)

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: - all 23.2 versions, - 23.4 versions before 23.4R2-S7-EVO,

CVE-2026-57029
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jul 9, 2026
Medium6.5Juniper

Medium [CVE-2026-57027] Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).When sFlow is configured in a Virtual Chassis (VC) scenario with EX4100 Series or EX4400 Series devices, multicast traffic which is received on one VC member and sent out on another member leads to a memory leak and ultimately an FPC crash and restart

A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).When sFlow is configured in a Virtual Chassis (VC) scenario with EX4100 Series or EX4400 Series devices, multicast traffic which is received on one VC member and sent out on another member leads to a memory leak and ultimately an FPC crash and restart. The leak can be monitored by watching the continuous increase of the buffer values in the output of: user@host> show chassis fpc This issue affects Junos OS on EX4100 Series and EX4400: - all versions before 23.2R2-S7, - 23.4 versions before 23.4R2-S7, Affected products named by the advisory: EX. Affected products named by the advisory: EX.

CVE-2026-57027
SwitchesJunosEX / QFX SwitchesEX4100
Jul 9, 2026
Medium6.5Juniper

Medium [CVE-2026-57020] Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS)

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). On all QFX10000 platforms in an EVPN-VxLAN scenario, if an attacker sends IPv6 multicast traffic and these packets reach the non-IRB interface of a spine switch it floods the packet to other spines and all Ethernet Segment Identifier (ESI) leaf switches. This flooding causes the packet to be forwarded in a endless loop, which can lead to saturation of the involved links and in turn impact to legitimate traffic. This issue affects Junos OS on QFX10000 Series: - all versions before 23.2R2-S7, - 23.4 versions before 23.4R2-S8,

CVE-2026-57020
SwitchesJunos
Jul 9, 2026
Medium5.5Juniper

Medium [CVE-2026-33802] Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS)

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers. This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400: - 23.2R2 versions before 23.2R2-S6, - 23.4 versions before 23.4R2-S8, - 25.4 versions before 25.4R1-S1. Affected products named by the advisory: EX. Affected products named by the advisory: EX.

CVE-2026-33802
SwitchesJunosEX / QFX SwitchesEX2300
Jul 9, 2026
High7.4Juniper

High [CVE-2026-33771] Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2. Affected product named by the advisory: EX. Affected product named by the advisory: EX.

CVE-2026-33771
SwitchesEX / QFX Switches
Apr 9, 2026
High8.7Juniper

High [CVE-2025-13914] Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. This issue affects all versions of Apstra before 6.1.1. Affected product named by the advisory: EX. Affected product named by the advisory: EX.

CVE-2025-13914
SwitchesEX / QFX Switches
Apr 9, 2026
Medium6.5Juniper

Medium [CVE-2026-33781] Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS)

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS). On EX4k, and QFX5k platforms configured as service-provider edge devices, if L2PT is enabled on the UNI and VSTP is enabled on NNI in VXLAN scenarios, receiving VSTP BPDUs on UNI leads to packet buffer allocation failures, resulting in the device to not pass traffic anymore until it is manually recovered with a restart. This issue affects Junos OS: - 24.4 releases before 24.4R2, - 25.2 releases before 25.2R1-S1, 25.2R2. This issue does not affect Junos OS releases before 24.4R1. Affected products named by the advisory: EX. Affected products named by the advisory: EX.

CVE-2026-33781
SwitchesJunosEX / QFX Switches
Apr 9, 2026
Medium5.8Juniper

Medium [CVE-2026-33773] Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks

An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks. When the same family inet or inet6 filter is applied on an IRB interface and on a physical interface as egress filter on EX4100, EX4400, EX4650 and QFX5120 devices, only one of the two filters will be applied, which can lead to traffic being sent out one of these interfaces which should have been blocked. This issue affects Junos OS on EX Series and QFX Series: - 23.4 version 23.4R2-S6, - 24.2 version 24.2R2-S3. No other Junos OS versions are affected. Affected products named by the advisory: EX. Affected products named by the advisory: EX.

CVE-2026-33773
SwitchesJunosEX / QFX SwitchesEX4100
Apr 9, 2026
Medium6.7Juniper

Medium [CVE-2026-21915] Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu accepts input without carefully validating it, which allows for shell command injection. These shell commands are executed with root permissions and can be used to gain complete control of the system. This issue affects all JSI vLWC versions before 3.0.94. Affected product named by the advisory: EX. Affected product named by the advisory: EX.

CVE-2026-21915
SwitchesEX / QFX Switches
Apr 9, 2026
Medium6.5Juniper

Medium [CVE-2025-59969] Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).An attacker sending crafted multicast packets will cause line cards running evo-aftmand/evo-pfemand to crash and restart or non-line card devices to crash and restart

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).An attacker sending crafted multicast packets will cause line cards running evo-aftmand/evo-pfemand to crash and restart or non-line card devices to crash and restart. Continued receipt and processing of these packets will sustain the Denial of Service (DoS) condition. This issue affects Junos OS Evolved PTX Series: - All versions before 22.4R3-S8-EVO, - from 23.2 before 23.2R2-S5-EVO, - from 23.4 before 23.4R2-EVO, - 22.2-EVO version before 22.2R3-S7-EVO,

CVE-2025-59969
RoutersSwitchesJunosJunos OS Evolved
Apr 9, 2026
Medium6.7Juniper

Medium [CVE-2025-30650] Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: - MPC7, MPC8, MPC9, MPC10, MPC11 - LC2101, LC2103 - LC480, LC4800, LC9600 - MX304 (built-in FPC) - MX-SPC3 - EX9200-40XS - FPC3-PTX-U2, FPC3-PTX-U3 - LC1101, LC1102, LC1104, LC1105 - all versions before 22.4R3-S8, - from 23.2 before 23.2R2-S6, - from 23.4 before 23.4R2-S6, Affected products named by the advisory: MX. Affected products named by the advisory: MX.

CVE-2025-30650
RoutersSwitchesJunosMX / Routers
Apr 8, 2026
Critical9.8Juniper

Critical [CVE-2026-21902] Junos: Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper…

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: - 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS. Affected products named by the advisory: EX.

CVE-2026-21902
RoutersSwitchesJunosJunos OS Evolved
Feb 25, 2026
High7.5Juniper

High [CVE-2026-21913] Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on…

An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted. The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message: reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP: - 24.4 versions before 24.4R2, - 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1. Affected products named by the advisory: EX.

CVE-2026-21913
SwitchesJunosEX / QFX SwitchesEX4000
Jan 15, 2026
High7.1Juniper

High [CVE-2026-21908] Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and…

A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the process running as root. The issue is specific to the processing of a change in authorization (CoA) when a port bounce occurs. A pointer is freed but was then referenced later in the same code path. Successful exploitation is outside the attacker's direct control due to the specific timing of the two events required to execute the vulnerable code path. This issue affects systems with 802.1X authentication port-based network access control (PNAC) enabled. - from 23.2R2-S1 before 23.2R2-S5, - from 23.4R2 before 23.4R2-S6, Affected products named by the advisory: EX.

CVE-2026-21908
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21906] Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS…

An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE to crash and restart. When PowerMode IPsec (PMI) and GRE performance acceleration are enabled and the device receives a specific ICMP packet, a crash occurs in the SRX PFE, resulting in traffic loss. PMI is enabled by default, and GRE performance acceleration can be enabled by running the configuration command shown below. PMI is a mode of operation that provides IPsec performance improvements using Vector Packet Processing. Note that PMI with GRE performance acceleration is only supported on specific SRX platforms. This issue affects Junos OS on the SRX Series: - all versions before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S5, Affected products named by the advisory: EX.

CVE-2026-21906
SRXFirewallSwitchesJunos
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21905] Junos: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper…

A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC. This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue. - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S6, Affected products named by the advisory: MX; EX.

CVE-2026-21905
SRXFirewallRoutersSwitches
Jan 15, 2026
High7.5Juniper

High [CVE-2025-60003] Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved

A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives a BGP update with a set of specific optional transitive attributes over an established peering session, rpd will crash and restart when attempting to advertise the received information to another peer. This issue can only happen if one or both of the BGP peers of the receiving session are non-4-byte-AS capable as determined from the advertised capabilities during BGP session establishment. Junos OS and Junos OS Evolved default behavior is 4-byte-AS capable unless this has been specifically disabled by configuring: [ protocols bgp... disable-4byte-as ] Established BGP sessions can be checked by executing: show bgp neighbor | match "4 byte AS" This issue affects: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5, - 23.4 versions before 23.4R2-S6, Affected products named by the advisory: EX.

CVE-2025-60003
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
High7.4Juniper

High [CVE-2025-59960] Junos: Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server. By default, the DHCP relay agent inserts its own Option 82 information when forwarding client requests, optionally replacing any Option 82 information provided by the client. When a specific DHCP DISCOVER is received in 'forward-only' mode with Option 82, the device should drop the message unless 'trust-option82' is configured. Instead, the DHCP relay forwards these packets to the DHCP server unmodified, which uses up addresses in the DHCP server's address pool, ultimately leading to address pool exhaustion. This issue affects Junos OS: - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S6, - all versions of 22.2-EVO, - from 22.4 before 22.4R3-S8-EVO, Affected products named by the advisory: EX.

CVE-2025-59960
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
Medium5.5Juniper

Medium [CVE-2026-21912] Junos: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of…

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged attacker executing the 'show system firmware' CLI command to cause an LC480 or LC2101 line card to reset. On MX10k Series systems with LC480 or LC2101 line cards, repeated execution of the 'show system firmware' CLI command can cause the line card to crash and restart. Additionally, some time after the line card crashes, chassisd may also crash and restart, generating a core dump. This issue affects Junos OS on MX10k Series: - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S9, - from 23.2 before 23.2R2-S2, - from 23.4 before 23.4R2-S3, Affected products named by the advisory: MX; EX.

CVE-2026-21912
RoutersSwitchesJunosMX / Routers
Jan 15, 2026

← All Juniper advisories