NCSC-2026-0224 [1.00] [M/H] Vulnerabilities fixed in Juniper Networks Junos OS and Junos OS Evolved
Juniper has fixed multiple vulnerabilities in Junos OS and Junos OS Evolved, specifically for MX Series, PTX Series, QFX Series, EX Series, SRX Series, and QFX10000 Series devices. The vulnerabilities affect various components within Junos OS and Junos OS Evolved, including the packet forwarding engine, routing protocol daemon, management daemon, SNMP daemon, http-gatekeeper, TCP proxy plugin, IKE daemon, fileio library, SIP plugin, URL filtering plugin, and CLI. Exploitation can lead to memory corruption, crashes of processes such as mgd, rpd, flow processing daemon, l2ald, and FPC, resulting in Denial-of-Service (DoS) conditions. Some vulnerabilities can be exploited by local users with limited privileges to execute code or crash processes. Other vulnerabilities can be exploited by unauthenticated attackers via network traffic to crash processes, leak information, cause license exhaustion, or bypass firewall rules. Specific hardware models and software versions are affected, such as MX Series with SPC3, SRX Series, EX Series (EX2300, EX4000, EX4100, EX4400), QFX Series, PTX Series, and QFX10000 Series. Some vulnerabilities require manual restart of systems or processes to restore normal operation. The issues are present in versions prior to the published patches and updates.
CSIRTS triage
- What
- Multiple vulnerabilities can lead to memory corruption and denial-of-service conditions.
- Who is affected
- Devices running Junos OS and Junos OS Evolved, including MX Series, PTX Series, QFX Series, EX Series, SRX Series, and QFX10000 Series, are affected.
- Urgency
- Remediation is urgent as some vulnerabilities can be exploited by unauthenticated attackers, leading to crashes and information leaks.
- Action
- Apply the latest patches provided by Juniper to address the vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Junos OS
Get an email when a new Junos OS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0224
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2020-74502.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 83% of all scored CVEs.
- Low exploitation riskCVE-2026-219010.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-337940.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-337990.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-338000.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-338010.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-338020.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-338030.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-570190.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-570200.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Juniper JUNOS and JUNOS Evolved: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-57054: A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of J…nvd
- mediumCVE-2026-57032: An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pf…nvd
- mediumCVE-2026-57031: An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding…nvd
- mediumCVE-2026-57030: A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') …nvd
- mediumCVE-2026-57029: A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Juno…nvd
- highCVE-2026-57028: An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Junipe…nvd
- mediumCVE-2026-57027: A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding en…nvd
- highCVE-2026-57026: An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Ju…nvd
- mediumCVE-2026-57025: A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Jun…nvd
- mediumCVE-2026-57024: A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) o…nvd
- highCVE-2026-57023: An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of…nvd
Recent advisories for Juniper Networks Junos
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-57054: A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of J…nvd · 2026-07-09
- mediumCVE-2026-57032: An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pf…nvd · 2026-07-09
- mediumCVE-2026-57031: An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding…nvd · 2026-07-09
- mediumCVE-2026-57030: A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') …nvd · 2026-07-09
- mediumCVE-2026-57029: A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Juno…nvd · 2026-07-09
- highCVE-2026-57028: An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Junipe…nvd · 2026-07-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0268 [1.01] [M/H] Kwetsbaarheid verholpen in SQLite door SQLite Consortium (ingetrokken)2026-08-03
- unknownNCSC-2026-0275 [1.00] [M/H] Kwetsbaarheden verholpen in N-able N-central2026-08-03
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31