Juniper disclosed two security vulnerabilities affecting Junos OS and Junos OS Evolved, including a local privilege-escalation flaw tracked as CVE-2026-21916 that allows a low-privileged user to escalate privileges and log in as root. The issue creates a path for attackers who already have limited access to gain full administrative control over affected devices, increasing the risk of device takeover and unauthorized configuration changes.
Juniper also published an advisory for CVE-2026-21919, a denial-of-service condition in Junos OS and Junos OS Evolved where a high frequency of connecting and disconnecting NETCONF sessions can cause management-plane unavailability. The flaw can disrupt administrative access and network operations by making device management unavailable, compounding the impact of the privilege-escalation issue for organizations running affected Juniper infrastructure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Juniper published a security bulletin for CVE-2026-33782 affecting Junos OS on MX Series devices. The bulletin says that in specific DHCPv6 scenarios, jdhcpd memory increases continuously with subscriber logouts.
Juniper published a security bulletin for CVE-2026-33793 affecting Junos OS and Junos OS Evolved, warning that when an unsigned Python op script configuration is present, a local low-privileged user can compromise the system.
Juniper published a security bulletin for CVE-2026-21919 affecting Junos OS and Junos OS Evolved, describing a denial-of-service condition where frequent connection and disconnection of NETCONF sessions can cause management unavailability.
Juniper published a security bulletin for CVE-2026-21916 affecting Junos OS, describing a flaw that could allow a low-privileged user to escalate privileges and log in as root.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.