Juniper disclosed a critical remote code execution vulnerability in Junos OS Evolved running on PTX Series routers that can allow an unauthenticated, network-based attacker to execute code as root and potentially take full control of affected devices (CVE-2026-21902). The flaw stems from incorrect permission assignment in the On-Box Anomaly Detection framework, which is intended to be reachable only by internal processes over an internal routing instance but is exposed via an externally reachable port; the vulnerable service runs as root and is enabled by default.
Affected versions are 25.4 releases prior to 25.4R1-S1-EVO and 25.4R2-EVO on PTX Series; standard (non-Evolved) Junos OS and Junos OS Evolved versions before 25.4R1-EVO are not impacted. Juniper released fixes in 25.4R1-S1-EVO, 25.4R2-EVO, and 26.2R1-EVO, and at the time of advisory publication stated it was not aware of active exploitation; guidance includes prioritizing patching and, where immediate updates are not possible, restricting access to the exposed endpoints using firewall filters/ACLs. The Canadian Centre for Cyber Security echoed the vendor advisory and urged administrators to apply the updates.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
In its disclosure and related reporting, Juniper said it was not aware of active exploitation of CVE-2026-21902 at the time the bulletin was issued. The company also recommended interim mitigations such as ACLs, firewall filters, or disabling the affected service.
On 2026-02-25, the Canadian Centre for Cyber Security published advisory AV26-172 highlighting Juniper's disclosure of CVE-2026-21902. It urged administrators to review Juniper's guidance and apply the necessary updates.
On 2026-02-25, Juniper disclosed CVE-2026-21902 in advisory JSA107128, describing a critical unauthenticated remote code execution flaw that can lead to root-level compromise on exposed PTX Series devices running Junos OS Evolved 25.4. Juniper released fixed versions including 25.4R1-S1-EVO and 25.4R2-EVO, and multiple reports also cite 26.2R1-EVO as a patched release.
Juniper SIRT said CVE-2026-21902 was identified through internal product security testing. The flaw affects the On-Box Anomaly Detection framework in Junos OS Evolved on PTX Series routers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
11 references tracked. Mallory keeps watching after this page renders.
upguard.com
Open sourcethecyberthrone.in
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecsa.gov.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.