Juniper Networks disclosed two Junos OS vulnerabilities affecting multiple product lines that can trigger sustained memory growth and service disruption under specific network conditions. On MX Series devices, CVE-2026-33782 causes the jdhcpd process to continuously increase memory usage in certain DHCPv6 scenarios involving subscriber logouts, creating a risk of resource exhaustion on affected systems.
A separate flaw, CVE-2026-33781, impacts EX Series and QFX Series switches in VXLAN deployments, where receipt of specific control-protocol packets can cause a memory leak that eventually results in a state where no traffic is passed. The advisories indicate that both issues are denial-of-service style conditions tied to memory exhaustion, with the affected behavior depending on particular protocol and deployment scenarios in Juniper environments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Juniper issued a security bulletin for CVE-2026-33775 affecting Junos OS MX Series devices. The advisory describes a memory leak in bbe-smgd caused by a mismatch between configured and received packet types.
Juniper issued a security bulletin for CVE-2026-33782 affecting Junos OS MX Series devices. In specific DHCPv6 scenarios, the jdhcpd process memory increases continuously with subscriber logouts.
Juniper issued a security bulletin describing CVE-2026-33781 affecting Junos OS on EX Series and QFX Series devices. In a VXLAN scenario, receipt of specific control protocol packets can cause memory leaks and eventually prevent traffic from being passed.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.