Juniper disclosed two denial-of-service vulnerabilities in Junos OS Evolved affecting PTX Series routers, with one issue also impacting the QFX5000 Series. The first flaw, tracked as CVE-2025-59969, allows an attacker to send crafted multicast packets that cause the evo-aftmand and evo-pfemand processes to crash and restart, disrupting forwarding-related functions on affected devices.
A second vulnerability, CVE-2026-33783, affects PTX systems where SR-TE tunnels provisioned via PCEP are present; under those conditions, specific gRPC queries can trigger a crash in the evo-aftman process. Together, the advisories describe service instability risks in carrier-grade routing platforms, with crashes tied to malformed network traffic and management-plane queries rather than code execution.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Juniper published a security bulletin for CVE-2026-33783, reporting that on PTX Series systems with SR-TE tunnels provisioned via PCEP, specific gRPC queries can crash evo-aftman.
Juniper published a security bulletin for CVE-2025-59969, stating that crafted multicast packets can cause evo-aftmand and evo-pfemand to crash and restart on affected Junos OS Evolved PTX Series and QFX5000 Series devices.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.