By vendor

Juniper vulnerabilities

Known CVEs affecting Juniper products, prioritized by severity, with SEC.co remediation and detection guidance.

19 published vulnerabilities

  • CVE-2026-57023HIGH 7.5

    A flaw in Juniper Networks' TCP proxy functionality allows an attacker on the network to send a specially crafted TCP packet that crashes the flow processing daemon on vulnerable MX and SRX series routers. The crash causes a complete service outage until the system automatically restarts. No authentication is required—an attacker anywhere on the network can trigger this denial of service.

  • CVE-2026-57026HIGH 7.5

    Juniper Networks has disclosed a vulnerability in the SIP (Session Initiation Protocol) plugin used by MX Series and SRX Series routers running Junos OS. When SIP ALG (Application Layer Gateway) is enabled, a malformed SIP packet can crash the flow processing daemon, bringing the device offline until it automatically restarts. An attacker on the network can trigger this crash without authentication, making it a straightforward denial-of-service vector. The vulnerability affects a wide range of Junos OS versions across multiple release trains.

  • CVE-2026-57028HIGH 7.3

    Juniper Networks Junos OS Evolved contains a flaw that exposes an internal license management process to the network. An attacker without credentials can reach this normally internal-only function over the internet and trigger license exhaustion, effectively denying service to legitimate users. The vulnerability stems from improper initialization of network communication boundaries.

  • CVE-2026-33801MEDIUM 6.5

    A flaw in Juniper Networks' routing daemon allows an attacker already connected to a BGP neighbor to crash the routing system by sending a malformed network update. The attacker must be directly connected to the device (adjacent network access), but does not need to authenticate. When triggered, the routing daemon restarts, causing all routes to stop working temporarily until the system recovers. The impact is contained to the affected device—malicious routes are not forwarded downstream.

  • CVE-2026-33803MEDIUM 6.5

    A configuration flaw in Juniper Networks Junos OS Evolved exposes an internal process to the network that should remain isolated. An attacker can reach this process over the internet without authentication, potentially gathering limited device information and degrading performance by consuming CPU resources. The vulnerability affects multiple Junos OS Evolved release branches and requires a software update to resolve.

  • CVE-2026-57019MEDIUM 6.5

    A vulnerability in Juniper Networks Junos OS on MX Series routers allows an attacker on the same local network to crash a Forwarding Card (FPC) by sending a specially crafted packet. The device incorrectly calculates packet size in certain traffic scenarios, causing processing to fail and triggering a hardware reset. While the system recovers automatically, traffic is interrupted until that recovery completes, making this a localized denial-of-service risk for networks running vulnerable MX platforms.

  • CVE-2026-57020MEDIUM 6.5

    Juniper Networks QFX10000 switches running Junos OS contain a flaw in how they handle IPv6 multicast traffic in EVPN-VxLAN environments. When an attacker on the same network segment sends malicious IPv6 multicast packets to a spine switch's non-IRB interface, the switch forwards them in an endless loop across fabric links and leaf switches. This causes network congestion that can degrade or block legitimate traffic. The vulnerability requires adjacent network access but no authentication, making it exploitable by insider threats or compromised devices on the same segment.

  • CVE-2026-57027MEDIUM 6.5

    Juniper Junos OS running on EX4100 and EX4400 Series switches contains a memory leak in the packet forwarding engine when sFlow monitoring is enabled in a Virtual Chassis configuration. When multicast traffic crosses between chassis members, memory accumulates and is never freed, eventually exhausting buffer capacity and crashing the forwarding processor. An attacker on the adjacent network segment can trigger this condition repeatedly to deny service to the affected switch.

  • CVE-2026-57032MEDIUM 6.5

    Juniper Networks EX Series switches have a vulnerability that allows authenticated users with basic access to crash the packet forwarding engine by requesting unsupported telemetry data through gRPC connections. When triggered, the forwarding processor (FPC) module crashes, taking the switch offline until it automatically restarts. This affects EX2300, EX3400, EX4000, EX4100, and EX4400 models running unpatched versions of Junos OS.

  • CVE-2026-33794MEDIUM 5.9

    Juniper Networks Junos OS Evolved on PTX Series routers contain a flaw in how they process routing updates that create unified-list ECMP (equal-cost multipath) routes. An unauthenticated attacker on the network can send specially crafted, continuous routing updates that trigger an unchecked condition in the evo-aftmand process running on the Packet Forwarding Engine (PFE). This causes internal state corruption and crashes the process, forcing the router offline or requiring manual intervention to recover. The attack depends on a sequence of network conditions outside the attacker's direct control, but represents a denial-of-service risk for affected PTX platforms.

  • CVE-2026-57022MEDIUM 5.9

    Juniper Networks Junos OS running on certain MX and SRX platforms contains a flaw in how the Packet Forwarding Engine handles exceptional network conditions. An attacker on the network can send a specially crafted packet to an affected device, causing the forwarding engine to crash and restart. During this restart, all traffic and services stop working until the system recovers automatically. This vulnerability requires the device to initiate an outbound connection to the attacker first, which limits exploitability but remains a concern for devices that perform active network operations like traffic inspection or probing.

  • CVE-2026-57030MEDIUM 5.9

    Juniper SRX Series firewalls contain a race condition in their packet forwarding engine that can be exploited by sending specially crafted network traffic to cause denial of service. The bug occurs during flow session cleanup—normally flows are removed after 3 seconds of inactivity, but a timing issue can cause the timeout to be set to over 10,000 seconds instead. This prevents flows from being cleaned up properly, causing session tables to accumulate stale entries until the device either stops forwarding traffic entirely or crashes and reboots.

  • CVE-2026-57054MEDIUM 5.8

    Juniper Networks MX Series routers running Junos OS contain a flaw in their web filtering plugin that allows attackers to bypass security controls and reach restricted web resources. The vulnerability stems from improper name or URL resolution logic—specifically, if configured to block certain destinations, a specially crafted URL request can slip past the filter and reach downstream systems that should be inaccessible. An attacker on the network does not need authentication to exploit this, making it a straightforward attack vector for network-based threats.

  • CVE-2026-33802MEDIUM 5.5

    A local authentication bypass in Juniper EX Series switches allows an already-logged-in user without special privileges to run a sensitive CLI command that crashes network traffic, effectively disabling the switch until it recovers on its own. The attacker must already have console or SSH access, but does not need administrative rights to cause the outage.

  • CVE-2026-57025MEDIUM 5.5

    A flaw in Juniper Networks Junos OS and Junos OS Evolved can crash a layer-2 network service when a low-privileged user runs specific diagnostic commands. The crash is temporary—the service restarts automatically—but causes a brief outage affecting all layer-2 switching and learning functions on EX, QFX, and MX series devices. This is a local attack requiring existing user access, not a remote threat.

  • CVE-2026-57021MEDIUM 5.3

    Juniper Networks Junos OS on SRX Series devices contain a memory handling flaw in their web management component that allows remote attackers to knock the system offline. If your SRX is configured to perform security checks before users log in to the VPN, an attacker can send specially crafted network traffic that crashes the web service, taking down VPN access, J-Web management, and firewall authentication until the service restarts on its own. No authentication or user interaction is needed to trigger this problem.

  • CVE-2026-57024MEDIUM 5.3

    Juniper's IKE daemon (iked) on MX devices with SPC3 and SRX Series routers contains a flaw that causes it to crash repeatedly when handling a large number of failed VPN connection attempts. The underlying issue stems from the daemon reusing peer index values that are already assigned, leading to internal state conflicts. Each time iked crashes, it becomes unable to establish new VPN tunnels or refresh existing ones until the entire system is rebooted. An attacker on the network can trigger this by initiating many unsuccessful VPN negotiations, effectively disabling VPN connectivity for an extended period.

  • CVE-2026-57029MEDIUM 5.3

    A synchronization flaw in Juniper's Junos OS Evolved operating system can crash the flow collector handler on QFX Series switches when sFlow collector reachability changes at the same moment the sFlow thread reads network routing data. An adjacent attacker without authentication can trigger this race condition, forcing the packet forwarding engine (evo-pfemand process) to restart and briefly interrupting all traffic until recovery completes. The vulnerability affects multiple recent versions of Junos OS Evolved on QFX10008, QFX10016, QFX51xx, and QFX52xx platforms.

  • CVE-2026-33799MEDIUM 4.3

    Juniper Networks Junos OS and Junos OS Evolved contain a memory management flaw in their SNMP daemon that can be triggered by authenticated attackers. By sending specially crafted SNMPv3 queries, an attacker can cause the snmpd process to leak memory. Over time, repeated exploitation exhausts available memory, forcing the process to crash and restart. This disrupts SNMP-based system monitoring until the process recovers. The vulnerability requires network access and valid SNMP credentials to exploit.