Juniper published security advisories for two separate flaws affecting its management and telemetry products. In Junos Space, the ilpFilter field on nLegacy.jsp is vulnerable to reflected cross-site scripting tracked as CVE-2026-21904, exposing users to client-side script injection if they interact with a crafted request or link.
Juniper also disclosed a shell escape vulnerability in JSI Virtual Lightweight Collector that can allow privilege escalation to root, tracked as CVE-2026-21915. The advisories indicate that organizations using either product should review affected versions and apply Juniper’s recommended updates or mitigations to reduce the risk of administrative compromise and unauthorized code execution on impacted systems.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Juniper published a security bulletin for CVE-2026-21919, describing a denial-of-service condition where a high frequency of connecting and disconnecting NETCONF sessions can cause management unavailability in Junos OS and Junos OS Evolved.
Juniper published a security bulletin for CVE-2026-21916, describing a privilege escalation flaw in Junos OS that could allow a low-privileged user to escalate privileges and log in as root.
Juniper published a security bulletin for CVE-2026-21915, describing a shell escape vulnerability in JSI Virtual Lightweight Collector that allows privilege escalation to root.
Juniper published a security bulletin for CVE-2026-21904, describing a reflected cross-site scripting issue in the ilpFilter field on nLegacy.jsp in Junos Space.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.