Juniper Networks disclosed CVE-2026-33782, a high-severity flaw in the jdhcpd DHCP daemon on Junos OS MX Series devices that can trigger a memory leak and lead to denial of service. The issue affects deployments using DHCPv6 over PPPoE or DHCPv6 over VLAN when Active lease query or Bulk lease query is enabled, causing memory consumption to increase with each subscriber logout until jdhcpd crashes and restarts.
The resulting process failure can cause complete service impact until recovery. Juniper said affected versions include all releases before 22.4R3-S1, 23.2 releases before 23.2R2, and 23.4 releases before 23.4R2. Administrators can monitor for abnormal growth in daemon memory usage with:
show system processes extensive | match jdhcpd

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Belgium's Centre for Cybersecurity Belgium published an advisory warning that Juniper Junos OS contains denial-of-service vulnerabilities CVE-2026-33782 and CVE-2026-33783, and urged organizations to patch immediately. This adds public notice of a second related CVE not reflected in the existing timeline.
Juniper published a security bulletin for CVE-2026-33782 identifying affected releases and the versions containing fixes. The advisory states that releases before 22.4R3-S1, 23.2R2, and 23.4R2 are affected, indicating those versions as remediation points.
Juniper Networks disclosed a vulnerability in the jdhcpd DHCP daemon on Junos OS MX Series devices that can cause a memory leak and eventual denial of service in specific DHCPv6 environments. The issue affects DHCPv6 over PPPoE or VLAN deployments using Active lease query or Bulk lease query, where repeated subscriber logouts steadily increase memory usage until jdhcpd crashes and restarts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcesupportportal.juniper.net
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.