Juniper disclosed CVE-2026-21902, a critical remote code execution vulnerability in Junos OS Evolved affecting PTX Series routers. The issue is an incorrect permission assignment for a critical resource in the On-Box Anomaly Detection framework; if the service is reachable over the network, an unauthenticated attacker can execute code as root, enabling full device takeover. The service is described as running as root and being enabled by default, increasing impact where exposure exists.
watchTowr researchers reported the flaw and published technical analysis indicating the affected framework is intended for internal process communication and “should only be reachable” via internal interfaces, but may become accessible depending on configuration. Juniper advised customers to restrict/filter access (e.g., via firewall rules or ACLs) and indicated a patch would follow; impacted releases called out include 25.4R1-S1-EVO and 25.4R2-EVO, while non-Evolved Junos OS releases prior to 25.4R1-EVO were reported as not impacted. Juniper stated it had no evidence of active exploitation at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
watchTowr Labs published a detailed analysis showing that the exposed On-Box Anomaly Detection service listens on TCP port 8160, runs as root, and can be abused to create commands and DAGs that lead to shell execution via subprocess.run with shell=True. The publication also referenced proof-of-concept and detection artifact tooling for validation and artifact creation.
Juniper disclosed CVE-2026-21902 as a critical vulnerability affecting Junos OS Evolved 25.4R1-S1-EVO and 25.4R2-EVO on PTX routers. The company said it had not observed exploitation in the wild and advised customers to restrict access with ACLs or firewalls while a patch was being developed.
watchTowr researchers identified and reported CVE-2026-21902 to Juniper Networks. The flaw affects the On-Box Anomaly Detection framework in Junos OS Evolved on PTX Series routers and can enable unauthenticated remote code execution as root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcelabs.watchtowr.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.