Skip to content
VulniPulse

Juniper Networks Security Advisories & CVEs

22 advisories tracked · Juniper SIRT (JSA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Juniper CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Juniper device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Juniper's recent advisories.

Official source

Juniper SIRT (JSA) via NVD

Juniper's advisory portal (kb.juniper.net) is a login-walled Salesforce app, so VulniPulse ingests Juniper SIRT (JSA) advisories from NVD, filtered to Juniper's own CNA (sirt@juniper.net) — official, machine-readable data with the affected Junos releases in each description. Junos on SRX/MX/EX/QFX and Junos Space are the common targets.

Latest Juniper advisories

High7.3Juniper

High [CVE-2026-57028] Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized access to the license management. This issue affects all Junos OS Evolved versions before 23.2R2-EVO.

CVE-2026-57028
JunosJunos OS Evolved
Jul 9, 2026
High7.5Juniper

High [CVE-2026-57026] Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart

An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX Series with SPC3 and SRX Series: - all versions before 23.2R2-S7, - 23.4 versions before 23.4R2-S8, - 25.4 versions before 25.4R1-S2. Affected products named by the advisory: MX. Affected products named by the advisory: MX.

CVE-2026-57026
SRXFirewallRoutersJunos
Jul 9, 2026
High7.5Juniper

High [CVE-2026-57023] Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS)

An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX with SPC3, and SRX Series: - 23.4 versions before 23.4R2-S7, - 24.2 versions before 24.2R2-S4, This issue does not affect releases before 23.4R1. Affected products named by the advisory: MX. Affected products named by the advisory: MX.

CVE-2026-57023
SRXFirewallRoutersJunos
Jul 9, 2026
High7.4Juniper

High [CVE-2026-33797] Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS)

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS). An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS: - 25.2 versions before 25.2R2 This issue does not affect Junos OS versions before 25.2R1. eBGP and iBGP are affected. IPv4 and IPv6 are affected.

CVE-2026-33797
JunosJunos OS Evolved
Apr 9, 2026
High7.8Juniper

High [CVE-2026-33793] Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation. This issue affects Junos OS: - All versions before 22.4R3-S7, - from 23.2 before 23.2R2-S4, - from 23.4 before 23.4R2-S6,

CVE-2026-33793
JunosJunos OS Evolved
Apr 9, 2026
High7.5Juniper

High [CVE-2026-33790] Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly crash the srxpfe process and sustain the Denial of Service (DoS) condition. During NAT64 translation, receipt of a specific, malformed ICMPv6 packet destined to the device will cause the srxpfe process to crash and restart. This issue cannot be triggered using IPv4 nor other IPv6 traffic. This issue affects Junos OS on SRX Series: - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S12, - from 23.2 before 23.2R2-S6, - from 23.4 before 23.4R2-S7,

CVE-2026-33790
SRXFirewallJunos
Apr 9, 2026
High7.8Juniper

High [CVE-2026-33788] Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct access to the installed FPCs as a high privileged user, which can potentially lead to a full compromise of the affected component. This issue affects Junos OS Evolved on PTX10004, PTX10008, PTX100016, with JNP10K-LC1201 or JNP10K-LC1202: - All versions before 21.2R3-S8-EVO,

CVE-2026-33788
RoutersJunosJunos OS EvolvedMX / Routers
Apr 9, 2026
High8.8Juniper

High [CVE-2026-33785] Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These commands are only meant to be executed by high privileged or users designated for Juniper Device Manager (JDM) / Connected Security Distributed Services (CSDS) operations as they will impact all aspects of the devices managed via the respective MX. This issue affects Junos OS on MX Series: - 24.4 releases before 24.4R2-S3, - 25.2 releases before 25.2R2. This issue does not affect Junos OS releases before 24.4. Affected products named by the advisory: MX. Affected products named by the advisory: MX.

CVE-2026-33785
RoutersJunosMX / Routers
Apr 9, 2026
High7.5Juniper

High [CVE-2026-33778] Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS)

An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). If an affected device receives a specifically malformed first ISAKMP packet from the initiator, the kmd/iked process will crash and restart, which momentarily prevents new security associations (SAs) for from being established. Repeated exploitation of this vulnerability causes a complete inability to establish new VPN connections. This issue affects Junos OS on - all versions before 22.4R3-S9, - 23.2 version before 23.2R2-S6, - 23.4 version before 23.4R2-S7, - 24.2 versions before 24.2R2-S4, - 24.4 versions before 24.4R2-S3, Affected products named by the advisory: MX. Affected products named by the advisory: MX.

CVE-2026-33778
SRXFirewallRoutersJunos
Apr 9, 2026
High7.4Juniper

High [CVE-2026-33771] Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2. Affected product named by the advisory: EX. Affected product named by the advisory: EX.

CVE-2026-33771
SwitchesEX / QFX Switches
Apr 9, 2026
High7.3Juniper

High [CVE-2026-21916] UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system

A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system. When after a user has performed a specific 'file link...' CLI operation, another user commits (unrelated configuration changes), the first user can login as root. This issue affects Junos OS: - all versions before 23.2R2-S7, - 23.4 versions before 23.4R2-S6, This issue does not affect versions 25.4R1 or later.

CVE-2026-21916
Junos
Apr 9, 2026
High8.7Juniper

High [CVE-2025-13914] Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. This issue affects all versions of Apstra before 6.1.1. Affected product named by the advisory: EX. Affected product named by the advisory: EX.

CVE-2025-13914
SwitchesEX / QFX Switches
Apr 9, 2026
High7.5Juniper

High [CVE-2026-21920] Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series

An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd will crash and restart, which causes a service interruption until the process has recovered. This issue affects Junos OS on SRX Series: - 23.4 versions before 23.4R2-S5, - 24.2 versions before 24.2R2-S1, This issue does not affect Junos OS versions before 23.4R1.

CVE-2026-21920
SRXFirewallJunos
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21918] Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of packets is encountered a double free happens. This causes flowd to crash and the respective FPC to restart. This issue affects Junos OS on SRX and MX Series: - all versions before 22.4R3-S7, - 23.2 versions before 23.2R2-S3, - 23.4 versions before 23.4R2-S4, Affected products named by the advisory: MX.

CVE-2026-21918
SRXFirewallRoutersJunos
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21917] Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS…

An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX device configured for UTM Web-Filtering receives a specifically malformed SSL packet, this will cause an FPC crash and restart. This issue affects Junos OS on SRX Series: - 23.2 versions from 23.2R2-S2 before 23.2R2-S5, - 23.4 versions from 23.4R2-S1 before 23.4R2-S5, Earlier versions of Junos are also affected, but no fix is available.

CVE-2026-21917
SRXFirewallJunos
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21914] Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series

An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos). If an SRX Series device receives a specifically malformed GPRS Tunnelling Protocol (GTP) Modify Bearer Request message, a lock is acquired and never released. This results in other threads not being able to acquire a lock themselves, causing a watchdog timeout leading to FPC crash and restart. This issue leads to a complete traffic outage until the device has automatically recovered. This issue affects Junos OS on SRX Series: - all versions before 22.4R3-S8, - 23.2 versions before 23.2R2-S5, - 23.4 versions before 23.4R2-S6,

CVE-2026-21914
SRXFirewallJunos
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21913] Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on…

An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted. The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message: reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP: - 24.4 versions before 24.4R2, - 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1. Affected products named by the advisory: EX.

CVE-2026-21913
SwitchesJunosEX / QFX SwitchesEX4000
Jan 15, 2026
High7.1Juniper

High [CVE-2026-21908] Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and…

A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the process running as root. The issue is specific to the processing of a change in authorization (CoA) when a port bounce occurs. A pointer is freed but was then referenced later in the same code path. Successful exploitation is outside the attacker's direct control due to the specific timing of the two events required to execute the vulnerable code path. This issue affects systems with 802.1X authentication port-based network access control (PNAC) enabled. - from 23.2R2-S1 before 23.2R2-S5, - from 23.4R2 before 23.4R2-S6, Affected products named by the advisory: EX.

CVE-2026-21908
SwitchesJunosJunos OS EvolvedEX / QFX Switches
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21906] Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS…

An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE to crash and restart. When PowerMode IPsec (PMI) and GRE performance acceleration are enabled and the device receives a specific ICMP packet, a crash occurs in the SRX PFE, resulting in traffic loss. PMI is enabled by default, and GRE performance acceleration can be enabled by running the configuration command shown below. PMI is a mode of operation that provides IPsec performance improvements using Vector Packet Processing. Note that PMI with GRE performance acceleration is only supported on specific SRX platforms. This issue affects Junos OS on the SRX Series: - all versions before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S5, Affected products named by the advisory: EX.

CVE-2026-21906
SRXFirewallSwitchesJunos
Jan 15, 2026
High7.5Juniper

High [CVE-2026-21905] Junos: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper…

A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC. This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue. - all versions before 21.2R3-S10, - from 21.4 before 21.4R3-S12, - from 23.2 before 23.2R2-S5, - from 23.4 before 23.4R2-S6, Affected products named by the advisory: MX; EX.

CVE-2026-21905
SRXFirewallRoutersSwitches
Jan 15, 2026

← All vendors