CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0224 [1.00] [M/H] Vulnerabilities fixed in Juniper Networks Junos OS and Junos OS Evolved

unknownCVE-2020-7450CVE-2026-21901CVE-2026-33794CVE-2026-33799CVE-2026-33800CVE-2026-33801
Juniper has fixed multiple vulnerabilities in Junos OS and Junos OS Evolved, specifically for MX Series, PTX Series, QFX Series, EX Series, SRX Series, and QFX10000 Series devices. The vulnerabilities affect various components within Junos OS and Junos OS Evolved, including the packet forwarding engine, routing protocol daemon, management daemon, SNMP daemon, http-gatekeeper, TCP proxy plugin, IKE daemon, fileio library, SIP plugin, URL filtering plugin, and CLI. Exploitation can lead to memory corruption, crashes of processes such as mgd, rpd, flow processing daemon, l2ald, and FPC, resulting in Denial-of-Service (DoS) conditions. Some vulnerabilities can be exploited by local users with limited privileges to execute code or crash processes. Other vulnerabilities can be exploited by unauthenticated attackers via network traffic to crash processes, leak information, cause license exhaustion, or bypass firewall rules. Specific hardware models and software versions are affected, such as MX Series with SPC3, SRX Series, EX Series (EX2300, EX4000, EX4100, EX4400), QFX Series, PTX Series, and QFX10000 Series. Some vulnerabilities require manual restart of systems or processes to restore normal operation. The issues are present in versions prior to the published patches and updates.

CSIRTS triage

What
Multiple vulnerabilities can lead to memory corruption and denial-of-service conditions.
Who is affected
Devices running Junos OS and Junos OS Evolved, including MX Series, PTX Series, QFX Series, EX Series, SRX Series, and QFX10000 Series, are affected.
Urgency
Remediation is urgent as some vulnerabilities can be exploited by unauthenticated attackers, leading to crashes and information leaks.
Action
Apply the latest patches provided by Juniper to address the vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Junos OS

Get an email when a new Junos OS advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-13
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0224

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2020-7450coverage & exploitation statusNVD · CVE.org
CVE-2026-21901coverage & exploitation statusNVD · CVE.org
CVE-2026-33794coverage & exploitation statusNVD · CVE.org
CVE-2026-33799coverage & exploitation statusNVD · CVE.org
CVE-2026-33800coverage & exploitation statusNVD · CVE.org
CVE-2026-33801coverage & exploitation statusNVD · CVE.org
CVE-2026-33802coverage & exploitation statusNVD · CVE.org
CVE-2026-33803coverage & exploitation statusNVD · CVE.org
CVE-2026-57019coverage & exploitation statusNVD · CVE.org
CVE-2026-57020coverage & exploitation statusNVD · CVE.org
CVE-2026-57021coverage & exploitation statusNVD · CVE.org
CVE-2026-57022coverage & exploitation statusNVD · CVE.org
CVE-2026-57023coverage & exploitation statusNVD · CVE.org
CVE-2026-57024coverage & exploitation statusNVD · CVE.org
CVE-2026-57025coverage & exploitation statusNVD · CVE.org
CVE-2026-57026coverage & exploitation statusNVD · CVE.org
CVE-2026-57027coverage & exploitation statusNVD · CVE.org
CVE-2026-57028coverage & exploitation statusNVD · CVE.org
CVE-2026-57029coverage & exploitation statusNVD · CVE.org
CVE-2026-57030coverage & exploitation statusNVD · CVE.org
CVE-2026-57031coverage & exploitation statusNVD · CVE.org
CVE-2026-57032coverage & exploitation statusNVD · CVE.org
CVE-2026-57054coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Juniper Networks Junos

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories