PatchSiren

Juniper CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Juniper CVE published 2025-10-02

CVE-2015-7755

CVE-2015-7755 is a Juniper ScreenOS improper authentication vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The KEV entry points to Juniper’s out-of-cycle security bulletin for ScreenOS issues and instructs defenders to apply vendor mitigations promptly, or discontinue use of the product if mitigations are unavailable.

Known exploited Juniper CVE published 2025-03-13

CVE-2025-21590

CVE-2025-21590 is a Juniper Junos OS vulnerability classified as improper isolation or compartmentalization and listed in CISA’s Known Exploited Vulnerabilities catalog on 2025-03-13. The vendor bulletin referenced in the source metadata describes the issue as allowing a local attacker with shell access to execute arbitrary code. Because it is already in KEV, defenders should treat it as a priority remedi [truncated]

Known exploited Juniper CVE published 2023-11-13

CVE-2023-36851

CVE-2023-36851 is a Juniper Junos OS SRX Series vulnerability described as a missing authentication issue for a critical function. It was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on 2023-11-13, which makes it a high-priority item for defenders. The supplied official records do not include CVSS data or detailed affected-version scope, so the safest response is to treat exposed Juniper [truncated]

Known exploited Juniper CVE published 2023-11-13

CVE-2023-36847

CVE-2023-36847 is a Juniper Junos OS EX Series vulnerability described as a missing authentication for a critical function issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-13, which means defenders should treat it as actively abused and prioritize mitigation immediately. The official CISA guidance is to apply vendor mitigations or discontinue use of the product if mitigations [truncated]

Known exploited Juniper CVE published 2023-11-13

CVE-2023-36846

CVE-2023-36846 is a Juniper Junos OS SRX Series vulnerability described as a missing authentication issue for a critical function. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-13, which means defenders should treat it as an urgent remediation item rather than a routine patch task. The safest response is to follow Juniper’s vendor guidance immediately and, if mitigation is not av [truncated]

Known exploited Juniper CVE published 2023-11-13

CVE-2023-36845

CVE-2023-36845 is a Juniper Junos OS issue affecting EX Series and SRX Series devices. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-13, with a remediation due date of 2023-11-17, which indicates active exploitation concerns and an urgent defensive response window. The vendor bulletin referenced by CISA describes related J-Web issues that can be combined to enable pre-authenticat [truncated]

Known exploited Juniper CVE published 2023-11-13

CVE-2023-36844

CVE-2023-36844 is a Juniper Junos OS EX Series PHP external variable modification vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2023-11-13. For defenders, the urgent takeaway is that this is not just a theoretical issue: CISA has marked it as actively exploited and set a remediation due date of 2023-11-17 in the supplied timeline. Juniper’s advisory context, referenced in [truncated]

Known exploited Juniper CVE published 2022-03-25

CVE-2020-1631

CVE-2020-1631 is a Juniper Junos OS path traversal vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-25. The provided official sources confirm known exploitation status, but they do not include detailed impact, affected versions, or attack prerequisites. Because it is a KEV-listed issue, organizations running Junos OS should treat remediation as urgent and follow Juni [truncated]