Juniper Networks Security Advisories & CVEs
49 advisories tracked · Juniper SIRT (JSA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Juniper CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Juniper device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Juniper's recent advisories.
Official source
Juniper SIRT (JSA) via NVD
Juniper's advisory portal (kb.juniper.net) is a login-walled Salesforce app, so VulniPulse ingests Juniper SIRT (JSA) advisories from NVD, filtered to Juniper's own CNA (sirt@juniper.net) — official, machine-readable data with the affected Junos releases in each description. Junos on SRX/MX/EX/QFX and Junos Space are the common targets.
Latest Juniper advisories
Medium [CVE-2026-21909] Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos…
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition. Memory usage can be monitored through the use of the 'show task memory detail' command. For example: user@junos> show task memory detail | match ted-infra TED-INFRA-COOKIE 25 1072 28 1184 229 TED-INFRA-COOKIE 31 1360 34 1472 307 This issue affects: - from 23.2 before 23.2R2, - from 23.4 before 23.4R1-S2, 23.4R2, - from 24.1 before 24.1R2; This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO. Affected products named by the advisory: EX.
Medium [CVE-2026-21907] Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space allows the use of static key ciphers (ssl-static-key-ciphers), reducing the confidentiality of on-path traffic communicated across the connection. These ciphers also do not support Perfect Forward Secrecy (PFS), affecting the long-term confidentiality of encrypted communications. This issue affects all versions of Junos Space before 24.1R5.
Medium [CVE-2026-21903] Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS
A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS). Subscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart. The issue was not seen when YANG packages for the specific sensors were installed. This issue affects Junos OS: - all versions before 22.4R3-S7, - 23.2 version before 23.2R2-S4, - 23.4 versions before 23.4R2.
Medium [CVE-2026-0203] Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS). When an ICMP packet is received with a specifically malformed IP header value, the FPC receiving the packet crashes and restarts. Due to the specific type of malformed packet, adjacent upstream routers would not forward the packet, limiting the attack surface to adjacent networks. This issue only affects ICMPv4. ICMPv6 is not vulnerable to this issue. This issue does not affect AFT-based line cards such as the MPC10, MPC11, LC4800, LC9600, and MX304. This issue affects Junos OS: - all versions before 21.2R3-S9, - from 21.4 before 21.4R3-S10, - from 22.3 before 22.3R3-S4, - from 23.2 before 23.2R2-S3, - from 23.4 before 23.4R2-S3, Affected products named by the advisory: MX; EX.
Medium [CVE-2025-60011] Junos: Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks…
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. When an affected device receives a specific optional, transitive BGP attribute over an existing BGP session, it will be erroneously modified before propagation to peers. When the attribute is detected as malformed by the peers, these peers will most likely terminate the BGP sessions with the affected devices and thereby cause an availability impact due to the resulting routing churn. This issue affects: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5 - 23.4 versions before 23.4R2-S6, Affected products named by the advisory: EX.
Medium [CVE-2025-60007] NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series
A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). When a user executes the 'show chassis' command with specifically crafted options, chassisd will crash and restart. Due to this all components but the Routing Engine (RE) in the chassis are reinitialized, which leads to a complete service outage, which the system automatically recovers from. This issue affects: Junos OS on MX, SRX and EX Series, except MX10000 Series and MX304: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5, - 23.4 versions before 23.4R2-S6, Affected products named by the advisory: MX; EX.
Medium [CVE-2025-59961] Junos: Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks…
An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the resource. This vulnerability allows any low-privileged user logged into the system to connect to the Unix socket and issue commands to manage the DHCP service, in essence, taking administrative control of the local DHCP server or DHCP relay. This issue affects: - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S6, - all versions before 22.4R3-S8-EVO,
Medium [CVE-2025-59959] Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS…
An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route detail' is executed, and at least one of the routes in the intended output has specific attributes, this will cause an rpd crash and restart. 'show route... extensive' is not affected. This issue affects: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5, - 23.4 versions before 23.4R2-S5, Affected products named by the advisory: EX.
Medium [CVE-2025-52987] clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights)
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control. This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1. Affected products named by the advisory: EX.