Network security
Juniper Networks advisories: every record the registers tie to its products
In one line
80 advisories are attributed to Juniper Networks products in this record, covering March 2022 to July 2026, and 7 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 0 register entries mention Juniper Networks without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.
Attributed
80
tied to a named product
Known exploited
7
in the CISA catalogue
Rated critical
10
by the register
Last checked
Jul 17, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Juniper Networks, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
0 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
73 of the 80 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2025-21590criticalKnown exploitedMar 13, 2025
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
- CVE-2023-36844criticalKnown exploitedNov 13, 2023
Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
- CVE-2023-36845criticalKnown exploitedNov 13, 2023
Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability
- CVE-2023-36846criticalKnown exploitedNov 13, 2023
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
- CVE-2023-36847criticalKnown exploitedNov 13, 2023
Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
- CVE-2023-36851criticalKnown exploitedNov 13, 2023
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
- CVE-2020-1631criticalKnown exploitedMar 25, 2022
Juniper Junos OS Path Traversal Vulnerability
- WID-SEC-2026-2257highCVSS 8.6Jul 10, 2026
Affected products: Juniper JUNOS, Juniper QFX Series, Juniper EX Series, Juniper SRX Series
- CVE-2026-57054mediumCVSS 6.9Jul 09, 2026
A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to…
- CVE-2026-57032highCVSS 7.1Jul 09, 2026
An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low…
- CVE-2026-57031mediumCVSS 5.3Jul 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass…
- CVE-2026-57030highCVSS 8.2Jul 09, 2026
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series…
- CVE-2026-57029mediumCVSS 6.0Jul 09, 2026
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a…
- CVE-2026-57028mediumCVSS 6.9Jul 09, 2026
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license…
- CVE-2026-57027highCVSS 7.1Jul 09, 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated…
- CVE-2026-57026highCVSS 8.7Jul 09, 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated…
- CVE-2026-57025mediumCVSS 6.8Jul 09, 2026
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a…
- CVE-2026-57024mediumCVSS 6.9Jul 09, 2026
A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated…
- CVE-2026-57023highCVSS 8.7Jul 09, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated…
- CVE-2026-57022highCVSS 8.2Jul 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an…
- CVE-2026-57021mediumCVSS 6.9Jul 09, 2026
An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a…
- CVE-2026-57020highCVSS 7.1Jul 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated…
- CVE-2026-57019highCVSS 7.1Jul 09, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent…
- CVE-2026-33803mediumCVSS 6.9Jul 09, 2026
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a…
- CVE-2026-33802mediumCVSS 6.8Jul 09, 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).
- CVE-2026-33801highCVSS 7.1Jul 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent…
- CVE-2026-33800highCVSS 7.1Jul 09, 2026
An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a…
- CVE-2026-33799mediumCVSS 5.3Jul 09, 2026
An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid…
- CVE-2026-33794highCVSS 8.2Jul 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an…
- CVE-2026-21901mediumCVSS 6.7Jul 09, 2026
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating…
- WID-SEC-2026-1022highCVSS 10.0Apr 10, 2026
Affected products: Juniper Apstra, Juniper JUNOS, Juniper QFX Series, Juniper MX Series
- CVE-2026-33791highCVSS 8.4Apr 09, 2026
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI…
- CVE-2026-33787mediumCVSS 6.8Apr 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a…
- CVE-2026-33785mediumCVSS 6.3Apr 09, 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will…
- CVE-2026-33784criticalCVSS 9.3Apr 09, 2026
A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take…
- CVE-2026-33783highCVSS 7.1Apr 09, 2026
A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low…
- CVE-2026-33778highCVSS 8.7Apr 09, 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an…
- CVE-2026-33776mediumCVSS 6.8Apr 09, 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information.
- CVE-2026-33774mediumCVSS 6.9Apr 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated…
- CVE-2026-33771criticalCVSS 9.1Apr 09, 2026
A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of…
- CVE-2025-13914highCVSS 7.0Apr 09, 2026
A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices.
- CVE-2026-33797highCVSS 7.1Apr 09, 2026
An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an…
- CVE-2026-33779highCVSS 8.3Apr 09, 2026
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get…
- CVE-2026-33775highCVSS 7.1Apr 09, 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an…
- CVE-2026-33782highCVSS 8.7Apr 09, 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to…
- CVE-2026-33780highCVSS 7.1Apr 09, 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent…
- CVE-2026-33773mediumCVSS 6.9Apr 09, 2026
An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an…
- CVE-2026-33786mediumCVSS 6.8Apr 09, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local…
- CVE-2026-21916highCVSS 7.0Apr 09, 2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to…
- CVE-2026-33788highCVSS 8.5Apr 09, 2026
A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated…
- CVE-2026-21919highCVSS 7.1Apr 09, 2026
An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a…
- CVE-2026-21915highCVSS 8.4Apr 09, 2026
A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to…
- CVE-2026-21904mediumCVSS 5.1Apr 09, 2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the list…
- CVE-2025-59969highCVSS 7.1Apr 09, 2026
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on…
- CVE-2026-33793highCVSS 8.5Apr 09, 2026
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root…
- CVE-2025-30650highCVSS 8.4Apr 08, 2026
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards…
- WID-SEC-2026-0535criticalCVSS 10.0Mar 04, 2026
Affected products: Juniper JUNOS
- WID-SEC-2025-0393highCVSS 9.8Jan 28, 2026
Affected products: Juniper Session Smart Router
- WID-SEC-2026-0117highCVSS 8.6Jan 16, 2026
Affected products: Juniper JUNOS, Juniper Junos Space
- WID-SEC-2025-1519highCVSS 9.6Oct 10, 2025
Affected products: Juniper MX Series, Juniper JUNOS, Juniper SRX Series, Juniper Security Director
- WID-SEC-2025-2238highCVSS 8.6Oct 10, 2025
Affected products: Juniper JUNOS
- WID-SEC-2023-0063highCVSS 9.8Oct 09, 2025
Affected products: Juniper Junos Space, Juniper Contrail Service Orchestration
- WID-SEC-2025-0794highCVSS 10.0Sep 05, 2025
Affected products: Amazon Linux 2, SUSE Linux, Juniper Junos Space
- WID-SEC-2024-0064highCVSS 10.0Apr 11, 2025
Affected products: Juniper Junos Space, Juniper MX Series, Juniper JUNOS, Juniper EX Series
- WID-SEC-2025-0777highCVSS 8.6Apr 10, 2025
Affected products: Juniper JUNOS
- WID-SEC-2025-0552mediumCVSS 4.4Mar 14, 2025
Affected products: Juniper JUNOS
- WID-SEC-2025-0031highCVSS 8.6Jan 09, 2025
Affected products: Juniper JUNOS
- WID-SEC-2024-3140highCVSS 9.8Jan 09, 2025
Affected products: Juniper JUNOS, Juniper Junos Space
- WID-SEC-2024-1591mediumCVSS 7.5Nov 12, 2024
Affected products: Juniper JUNOS
- WID-SEC-2024-1500mediumCVSS 7.5Jul 02, 2024
Affected products: Juniper JUNOS
- WID-SEC-2024-1082highCVSS 9.8May 10, 2024
Affected products: Juniper JUNOS
- WID-SEC-2024-0855highCVSS 8.8Apr 17, 2024
Affected products: Juniper MX Series, Juniper JUNOS, Juniper QFX Series, Juniper EX Series
- WID-SEC-2024-0222highCVSS 8.8Jan 26, 2024
Affected products: Juniper EX Series, Juniper JUNOS, Juniper SRX Series
- WID-SEC-2023-2636highCVSS 8.4Oct 13, 2023
Affected products: Juniper MX Series, Juniper JUNOS, Juniper SRX Series, Juniper QFX Series
- WID-SEC-2023-2092highCVSS 9.8Sep 29, 2023
Affected products: Juniper EX Series, Juniper SRX Series, Juniper JUNOS
- WID-SEC-2023-2212mediumCVSS 7.5Aug 30, 2023
Affected products: Juniper JUNOS
- WID-SEC-2023-1737highCVSS 10.0Jul 13, 2023
Affected products: Juniper JUNOS, Juniper MX Series, Juniper SRX Series, Juniper QFX Series
- WID-SEC-2023-1527mediumCVSS 7.5Jun 22, 2023
Affected products: Juniper JUNOS
- WID-SEC-2023-0951highCVSS 9.8Apr 17, 2023
Affected products: Juniper JUNOS, Juniper MX Series, Juniper SRX Series, Juniper QFX Series
- WID-SEC-2023-0083mediumCVSS 7.5Jan 12, 2023
Affected products: Juniper JUNOS
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 47 | Jul 09, 2026 |
| CERT-Bund security advisories | BSI, Federal Republic of Germany | 26 | Jul 10, 2026 |
| Known Exploited Vulnerabilities catalogue | CISA, United States | 7 | Mar 13, 2025 |
The entry counts here are the raw register totals for Juniper Networks, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does Juniper Networks have?
80 advisories in this record are tied by a register to a product of Juniper Networks. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any Juniper Networks vulnerabilities being actively exploited?
7 of the 80 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.
Why does this page show fewer CVEs for Juniper Networks than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 0 register entries name Juniper Networks without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the Juniper Networks advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean Juniper Networks is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full Juniper Networks record, including sources and open questions
