Skip to content
VulniPulse

Juniper Networks Switches Vulnerabilities & Security Advisories

28 advisories tracked · Juniper SIRT (JSA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Juniper Networks advisory that VulniPulse classified as Switches, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 8 high, 19 medium.

Android app · Google Play

Monitor Juniper CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Juniper SIRT (JSA) via NVD

Juniper's advisory portal (kb.juniper.net) is a login-walled Salesforce app, so VulniPulse ingests Juniper SIRT (JSA) advisories from NVD, filtered to Juniper's own CNA (sirt@juniper.net) — official, machine-readable data with the affected Junos releases in each description. Junos on SRX/MX/EX/QFX and Junos Space are the common targets.

Latest Juniper Switches advisories

Medium6.5Juniper

Medium [CVE-2026-21911] Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS Evolved

An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker flapping the management interface to cause the learning of new MACs over label-switched interfaces (LSI) to stop while generating a flood of logs, resulting in high CPU usage. When the issue is seen, the following log message will be generated: op:1 flag:0x6 mac:xx:xx:xx:xx:xx:xx bd:2 ifl:13302 reason:0(REASON_NONE) i-op:6(INTRNL_OP_HW_FORCE_DELETE) status:10 lstatus:10 err:26(GETIFBD_VALIDATE_FAILED) err-reason 4(IFBD_VALIDATE_FAIL_EPOCH_MISMATCH) hw_wr:0x4 ctxsync:0 fwdsync:0 rtt-id:51 p_ifl:0 fwd_nh:0 svlbnh:0 event:- smask:0x100000000 dmask:0x0 mplsmask 0x1 act:0x5800 extf:0x0 pfe-id 0 hw-notif-ifl 13302 programmed-ifl 4294967295 pseudo-vtep underlay-ifl-idx 0 stack:GET_MAC, ALLOCATE_MAC, GET_IFL, GET_IFF, GET_IFBD, STOP, This issue affects Junos OS Evolved: - all versions before 21.4R3-S7-EVO, - from 22.2 before 22.2R3-S4-EVO, - from 22.3 before 22.3R3-S3-EVO, - from 23.2 before 23.2R2-S1-EVO, - from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO. Affected products named by the advisory: EX.

CVE-2026-21911
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
Medium6.5Juniper

Medium [CVE-2026-21910] Junos: Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS). On all EX4k and QFX5k platforms, a link flap in an EVPN-VXLAN configuration Link Aggregation Group (LAG) results in Inter-VNI traffic dropping when there are multiple load-balanced next-hop routes for the same destination. This issue is only applicable to systems that support EVPN-VXLAN Virtual Port-Link Aggregation Groups (VPLAG), such as the QFX5110, QFX5120, QFX5200, EX4100, EX4300, EX4400, and EX4650. Service can only be restored by restarting the affected FPC via the 'request chassis fpc restart slot ' command. This issue affects Junos OS - all versions before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S5, Affected products named by the advisory: EX.

CVE-2026-21910
SwitchesJunosEX / QFX SwitchesQFX5110
Jan 15, 2026
Medium6.5Juniper

Medium [CVE-2026-21909] Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos…

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition. Memory usage can be monitored through the use of the 'show task memory detail' command. For example: user@junos> show task memory detail | match ted-infra TED-INFRA-COOKIE 25 1072 28 1184 229 TED-INFRA-COOKIE 31 1360 34 1472 307 This issue affects: - from 23.2 before 23.2R2, - from 23.4 before 23.4R1-S2, 23.4R2, - from 24.1 before 24.1R2; This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO. Affected products named by the advisory: EX.

CVE-2026-21909
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
Medium6.5Juniper

Medium [CVE-2026-0203] Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS). When an ICMP packet is received with a specifically malformed IP header value, the FPC receiving the packet crashes and restarts. Due to the specific type of malformed packet, adjacent upstream routers would not forward the packet, limiting the attack surface to adjacent networks. This issue only affects ICMPv4. ICMPv6 is not vulnerable to this issue. This issue does not affect AFT-based line cards such as the MPC10, MPC11, LC4800, LC9600, and MX304. This issue affects Junos OS: - all versions before 21.2R3-S9, - from 21.4 before 21.4R3-S10, - from 22.3 before 22.3R3-S4, - from 23.2 before 23.2R2-S3, - from 23.4 before 23.4R2-S3, Affected products named by the advisory: MX; EX.

CVE-2026-0203
RoutersSwitchesJunosMX / Routers
Jan 15, 2026
Medium5.8Juniper

Medium [CVE-2025-60011] Junos: Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. When an affected device receives a specific optional, transitive BGP attribute over an existing BGP session, it will be erroneously modified before propagation to peers. When the attribute is detected as malformed by the peers, these peers will most likely terminate the BGP sessions with the affected devices and thereby cause an availability impact due to the resulting routing churn. This issue affects: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5 - 23.4 versions before 23.4R2-S6, Affected products named by the advisory: EX.

CVE-2025-60011
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
Medium5.5Juniper

Medium [CVE-2025-60007] NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series

A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). When a user executes the 'show chassis' command with specifically crafted options, chassisd will crash and restart. Due to this all components but the Routing Engine (RE) in the chassis are reinitialized, which leads to a complete service outage, which the system automatically recovers from. This issue affects: Junos OS on MX, SRX and EX Series, except MX10000 Series and MX304: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5, - 23.4 versions before 23.4R2-S6, Affected products named by the advisory: MX; EX.

CVE-2025-60007
SRXFirewallRoutersSwitches
Jan 15, 2026
Medium5.5Juniper

Medium [CVE-2025-59959] Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS…

An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route detail' is executed, and at least one of the routes in the intended output has specific attributes, this will cause an rpd crash and restart. 'show route... extensive' is not affected. This issue affects: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5, - 23.4 versions before 23.4R2-S5, Affected products named by the advisory: EX.

CVE-2025-59959
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
Medium6.1Juniper

Medium [CVE-2025-52987] clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights)

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control. This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1. Affected products named by the advisory: EX.

CVE-2025-52987
SwitchesParagonEX / QFX Switches
Jan 15, 2026

← All Juniper advisories