Juniper
Juniper Junos: vulnerabilities and CVEs
Juniper Junos has 791 published vulnerabilities, 65 of them in the last 12 months. 38 are rated critical and 7 are listed by CISA as actively exploited.
CVEs791
Last 12 months65
Critical38
Actively exploited7
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21590 | Medium (6.7) | 1.7% | ⚠ Active exploitation | Mar 12, 2025 | An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access… |
| CVE-2023-36846 | Medium (5.3) | 93% | ⚠ Active exploitation | Aug 17, 2023 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a… |
| CVE-2023-36844 | Medium (5.3) | 90% | ⚠ Active exploitation | Aug 17, 2023 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a… |
| CVE-2023-36847 | Medium (5.3) | 83% | ⚠ Active exploitation | Aug 17, 2023 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a… |
| CVE-2023-36851 | Medium (5.3) | 1.1% | ⚠ Active exploitation | Sep 27, 2023 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a… |
| CVE-2023-36845 | Critical (9.8) | 95% | ⚠ Active exploitation | Aug 17, 2023 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request… |
| CVE-2020-1631 | Critical (9.8) | 4.8% | ⚠ Active exploitation | May 4, 2020 | A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57054 | Medium (6.9) | 0.37% | — | Jul 9, 2026 | A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access… |
| CVE-2026-57032 | High (7.1) | 0.42% | — | Jul 9, 2026 | An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a… |
| CVE-2026-57031 | Medium (5.3) | 0.22% | — | Jul 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On… |
| CVE-2026-57030 | High (8.2) | 0.38% | — | Jul 9, 2026 | A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated,… |
| CVE-2026-57027 | High (7.1) | 0.27% | — | Jul 9, 2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a… |
| CVE-2026-57026 | High (8.7) | 0.46% | — | Jul 9, 2026 | An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a… |
| CVE-2026-57025 | Medium (6.8) | 0.14% | — | Jul 9, 2026 | A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX… |
| CVE-2026-57024 | Medium (6.9) | 0.42% | — | Jul 9, 2026 | A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a… |
| CVE-2026-57023 | High (8.7) | 0.46% | — | Jul 9, 2026 | An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause… |
| CVE-2026-57022 | High (8.2) | 0.40% | — | Jul 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker… |
| CVE-2026-57021 | Medium (6.9) | 0.47% | — | Jul 9, 2026 | An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series… |
| CVE-2026-57020 | High (7.1) | 0.27% | — | Jul 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a… |
| CVE-2026-57019 | High (7.1) | 0.27% | — | Jul 9, 2026 | An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a… |
| CVE-2026-33802 | Medium (6.8) | 0.12% | — | Jul 9, 2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit)… |
| CVE-2026-33801 | High (7.1) | 0.28% | — | Jul 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a… |
| CVE-2026-33800 | High (7.1) | 0.27% | — | Jul 9, 2026 | An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service… |
| CVE-2026-33799 | Medium (5.3) | 0.37% | — | Jul 9, 2026 | An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory… |
| CVE-2026-21901 | Medium (6.7) | 0.17% | — | Jul 9, 2026 | A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration… |
| CVE-2026-33797 | High (7.1) | 0.27% | — | Apr 9, 2026 | An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to… |
| CVE-2026-33793 | High (8.5) | 0.17% | — | Apr 9, 2026 | An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the… |
| CVE-2026-33791 | High (8.4) | 0.67% | — | Apr 9, 2026 | An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell… |
| CVE-2026-33790 | High (8.7) | 0.46% | — | Apr 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the… |
| CVE-2026-33787 | Medium (6.8) | 0.13% | — | Apr 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a local attacker with low… |
| CVE-2026-33786 | Medium (6.8) | 0.13% | — | Apr 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to… |
| CVE-2026-33785 | Medium (6.3) | 0.14% | — | Apr 9, 2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of… |
| CVE-2026-33782 | High (8.7) | 0.55% | — | Apr 9, 2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will… |
| CVE-2026-33781 | High (7.1) | 0.27% | — | Apr 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker… |
| CVE-2026-33780 | High (7.1) | 0.28% | — | Apr 9, 2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a… |
| CVE-2026-33779 | High (8.3) | 0.18% | — | Apr 9, 2026 | An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential… |
| CVE-2026-33778 | High (8.7) | 0.46% | — | Apr 9, 2026 | An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker… |