VulnSea

juniper has 10 CVEs on record. Disclosures have slowed: 3 in the last 90 days after 7 in the 90 before. The busiest recent month was April 2026 with 7. The median CVSS is 6.6 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-754 (3). Most affected products: junos (4), virtual_lightweight_collector (2), apstra (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
Last 90 days
3 prev 7

Products

  • junos 4
  • virtual_lightweight_collector 2
  • apstra 1
  • ctop_os 1
  • junos_os_evolved 1
  • junos_space 1
10
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

juniper vulnerabilities

CVEs affecting juniper, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-57031Medium· 4.7
2mo ago

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series device…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series device…

Sunlitjuniper · junosEPSS 0.22%via NVD
CVE-2026-33799Medium· 4.3
2mo ago

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, c…

Sunlitjuniper · junosEPSS 0.37%via NVD
CVE-2026-33794Medium· 5.9
2mo ago

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating con…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating con…

Sunlitjuniper · junos_os_evolvedEPSS 0.40%via NVD
CVE-2026-33788High· 7.8
5mo ago

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …

Twilightjuniper · junosEPSS 0.11%via NVD
CVE-2026-33784Critical· 9.8
5mo ago

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images s…

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images s…

Midnightjuniper · virtual_lightweight_collectorEPSS 0.46%via NVD
CVE-2026-33774Medium· 6.5
5mo ago

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall fil…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall fil…

Sunlitjuniper · junosEPSS 0.17%via NVD
CVE-2026-33771High· 7.4
5mo ago

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full contro…

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full contro…

Twilightjuniper · ctop_osEPSS 0.26%via NVD
CVE-2026-21915Medium· 6.7
5mo ago

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…

Sunlitjuniper · virtual_lightweight_collectorEPSS 2.2%via NVD
CVE-2026-21904Medium· 6.1
5mo ago

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the list filter field that, when visited by another user,…

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the list filter field that, when visited by another user,…

Sunlitjuniper · junos_spaceEPSS 0.21%via NVD
CVE-2025-13914High· 8.7
5mo ago

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…

Twilightjuniper · apstraEPSS 0.30%via NVD
juniper vulnerabilities (CVEs) · VulnSea