PatchSiren

Juniper Networks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-57054

CVE-2026-57054 is a Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series. This vulnerability allows an unauthenticated, network-based attacker to bypass web filtering and access downstream resources that should be unreachable. The vulnerability exists due to improper resolution of names or references in the URL filtering plugin, [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57032

CVE-2026-57032 is an Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices. An authenticated attacker with low privileges can cause a Denial-of-Service (DoS) by attempting to subscribe to an unsupported telemetry sensor path via gRPC, causing the FPC to crash and leading to a complete service outage until the module [truncated]

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-57031

CVE-2026-57031 is an Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series. This allows adjacent subscribers to bypass configured firewall filters. The issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304 in various version ranges. Specifically, the vulnerability impacts devices with MPC10/11, L [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57030

A high-severity vulnerability, CVE-2026-57030, was found in Juniper Networks Junos OS on SRX Series devices. This vulnerability, caused by a race condition in the packet forwarding engine, allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability occurs during the removal of flows, where a timeout is set to a very high value, leading to an accumulation of flow [truncated]

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-57029

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data, it causes the evo-pf [truncated]

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-57028

CVE-2026-57028 is an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved. This issue allows an unauthenticated, network-based attacker to cause license exhaustion due to incorrect initialization of a process. The process, which should only communicate internally, can be reached over the network via an open port, leading to unauthorized acc [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57027

A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). The vulnerability is triggered when sFlow is configured in a Virtual Chassis (VC) scenario with EX4100 Series or EX4400 Series devices. In this scenario, multicast [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57026

CVE-2026-57026 is an Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series. This issue allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS) by processing a malformed SIP invite packet, leading to a flow processing daemon (flowd) crash and restart, resulting in a complete servi [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57023

CVE-2026-57023 is an Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series. This vulnerability allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57022

CVE-2026-57022 is a Denial-of-Service vulnerability in Juniper Networks Junos OS on MX with SPC3 and SRX Series. An unauthenticated, network-based attacker can cause a PFE crash and restart, affecting all services until the system recovers. The vulnerability is caused by an Improper Check for Unusual or Exceptional Conditions in the Packet Forwarding Engine (PFE). This issue can happen in various scenario [truncated]

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-57021

CVE-2026-57021 is an Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series. This vulnerability allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted requests can trigger a [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57020

CVE-2026-57020 is an Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper Networks Junos OS on QFX10000 Series. An unauthenticated, adjacent attacker can cause a Denial-of-Service (DoS) by sending IPv6 multicast traffic to the non-IRB interface of a spine switch in an EVPN-VxLAN scenario, leading to packet flooding and potential saturation of involved links. This issue affects Jun [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-57019

CVE-2026-57019 is an Improper Validation of Specified Quantity in Input vulnerability in Juniper Networks Junos OS on MX Series. An unauthenticated, adjacent attacker can cause a Denial-of-Service (DoS). The issue arises when a specific packet is received from a device in the same broadcast domain, causing the system to incorrectly calculate the packet size. This leads to further packet processing failure [truncated]

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-33803

CVE-2026-33803 Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-33801

CVE-2026-33801 is an Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved. An adjacent, unauthenticated attacker can send a specific BGP update to cause a Denial-of-Service (DoS). Upon receipt of a malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, causing a complete service outage until routing has reconverge [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-33800

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality-bias configured, processing takes [truncated]

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-33799

CVE-2026-33799 is an Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved. An authenticated network-based attacker can send specific valid SNMPv3 queries to trigger a memory leak, leading to snmpd process memory exhaustion, process crash, and restart. This impacts the ability to monitor the system via SNMP. Memory usage can be monitored using the c [truncated]

HIGH Juniper Networks CVE published 2026-07-09

CVE-2026-33794

CVE-2026-33794 is an Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series. This vulnerability allows an unauthenticated network-based attacker to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a s [truncated]

MEDIUM Juniper Networks CVE published 2026-07-09

CVE-2026-21901

A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS). The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart.

CRITICAL Juniper Networks CVE published 2026-04-09

CVE-2026-33784

CVE-2026-33784 is a Use of Default Password vulnerability in Juniper Networks Virtual Lightweight Collector (vLWC). The vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible. This issue affects all versions of vLWC before 3. [truncated]

MEDIUM Juniper Networks CVE published 2026-04-09

CVE-2026-33774

CVE-2026-33774 is an Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series. This vulnerability allows an unauthenticated, network-based attacker to bypass the configured firewall filter and access the control-plane of the device. The issue arises on MX platforms with specific line cards (MPC10, MPC11, LC4800, or L [truncated]

CRITICAL Juniper Networks CVE published 2026-04-09

CVE-2026-33771

CVE-2026-33771 is a Weak Password Requirements vulnerability in Juniper Networks CTP OS. The password management function does not enforce intended complexity requirements, allowing weak passwords and potentially leading to unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2. The vulnerability can be verified with the 'Show password requirements' menu option. Administrators and securit [truncated]

HIGH Juniper Networks CVE published 2026-04-08

CVE-2025-30650

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards, including MPC7, MPC8, MPC9, MPC10, MPC11, LC2101, LC2103, LC480, LC4800, LC9600, MX304, MX-SPC3, SRX5K-SPC3, EX9200-40XS, FPC3-PTX-U2, FP [truncated]