« Back to list

Juniper

Juniper Junos: vulnerabilities and CVEs

Juniper Junos has 791 published vulnerabilities, 65 of them in the last 12 months. 38 are rated critical and 7 are listed by CISA as actively exploited.

CVEs791
Last 12 months65
Critical38
Actively exploited7

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-21590Medium (6.7)1.7%⚠ Active exploitationMar 12, 2025
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access…
CVE-2023-36846Medium (5.3)93%⚠ Active exploitationAug 17, 2023
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a…
CVE-2023-36844Medium (5.3)90%⚠ Active exploitationAug 17, 2023
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a…
CVE-2023-36847Medium (5.3)83%⚠ Active exploitationAug 17, 2023
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a…
CVE-2023-36851Medium (5.3)1.1%⚠ Active exploitationSep 27, 2023
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a…
CVE-2023-36845Critical (9.8)95%⚠ Active exploitationAug 17, 2023
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request…
CVE-2020-1631Critical (9.8)4.8%⚠ Active exploitationMay 4, 2020
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-57054Medium (6.9)0.37%—Jul 9, 2026
A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access…
CVE-2026-57032High (7.1)0.42%—Jul 9, 2026
An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a…
CVE-2026-57031Medium (5.3)0.22%—Jul 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On…
CVE-2026-57030High (8.2)0.38%—Jul 9, 2026
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated,…
CVE-2026-57027High (7.1)0.27%—Jul 9, 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a…
CVE-2026-57026High (8.7)0.46%—Jul 9, 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a…
CVE-2026-57025Medium (6.8)0.14%—Jul 9, 2026
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX…
CVE-2026-57024Medium (6.9)0.42%—Jul 9, 2026
A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a…
CVE-2026-57023High (8.7)0.46%—Jul 9, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause…
CVE-2026-57022High (8.2)0.40%—Jul 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker…
CVE-2026-57021Medium (6.9)0.47%—Jul 9, 2026
An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series…
CVE-2026-57020High (7.1)0.27%—Jul 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a…
CVE-2026-57019High (7.1)0.27%—Jul 9, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a…
CVE-2026-33802Medium (6.8)0.12%—Jul 9, 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit)…
CVE-2026-33801High (7.1)0.28%—Jul 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a…
CVE-2026-33800High (7.1)0.27%—Jul 9, 2026
An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service…
CVE-2026-33799Medium (5.3)0.37%—Jul 9, 2026
An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory…
CVE-2026-21901Medium (6.7)0.17%—Jul 9, 2026
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration…
CVE-2026-33797High (7.1)0.27%—Apr 9, 2026
An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to…
CVE-2026-33793High (8.5)0.17%—Apr 9, 2026
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the…
CVE-2026-33791High (8.4)0.67%—Apr 9, 2026
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell…
CVE-2026-33790High (8.7)0.46%—Apr 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the…
CVE-2026-33787Medium (6.8)0.13%—Apr 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a local attacker with low…
CVE-2026-33786Medium (6.8)0.13%—Apr 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to…
CVE-2026-33785Medium (6.3)0.14%—Apr 9, 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of…
CVE-2026-33782High (8.7)0.55%—Apr 9, 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will…
CVE-2026-33781High (7.1)0.27%—Apr 9, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker…
CVE-2026-33780High (7.1)0.28%—Apr 9, 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a…
CVE-2026-33779High (8.3)0.18%—Apr 9, 2026
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential…
CVE-2026-33778High (8.7)0.46%—Apr 9, 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker…

Other products by Juniper