Juniper Networks disclosed multiple high-severity vulnerabilities in Junos OS and SRX/MX platforms, including remotely exploitable denial-of-service flaws and local privilege-escalation issues. The most exposed bugs include CVE-2026-33790, which lets an unauthenticated attacker crash the srxpfe packet forwarding engine on SRX Series firewalls by sending a malformed ICMPv6 packet to devices with NAT64 enabled, and CVE-2026-33778, which allows a malformed initial ISAKMP packet to crash the kmd or iked daemons on SRX and MX systems providing IPsec VPN services. Juniper said repeated exploitation can sustain outages by forcing affected processes into crash loops, and that fixes were released through security bulletins including JSA107874 and JSA107868.
Juniper also fixed CVE-2026-33785, a missing authorization flaw in MX Series routers that allows any locally authenticated user to run privileged request csds commands and potentially compromise managed infrastructure in JDM/CSDS deployments, and CVE-2026-21916, a symlink-handling bug in the Junos CLI that can let a low-privileged user gain root when another user performs a configuration commit. Affected versions span several supported Junos release trains, with fixes issued on April 8, 2026; some older branches, including certain end-of-life releases, do not have patches. Detection guidance from Juniper and Tenable relies largely on version auditing, configuration review for exposed features such as NAT64 and IPsec, and monitoring for daemon crashes, suspicious file link activity, unexpected root access, and abuse of privileged management commands.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
By 2026-04-09 reporting, Tenable had released version-based Nessus plugins for several newly disclosed Juniper vulnerabilities: plugin 305588 for CVE-2026-33790, 305590 for CVE-2026-33778, 305592 for CVE-2026-33785, and 305598 for CVE-2026-21916. These plugins provided detection coverage for affected Junos deployments.
On 2026-04-08, Juniper released fixes for CVE-2026-33790 across multiple supported Junos OS trains. Juniper also noted that some end-of-life branches, including 21.3 and 22.1, had no patch available.
On 2026-04-08, Juniper published advisory JSA107874 for CVE-2026-33790, a high-severity denial-of-service vulnerability in SRX Series firewalls with NAT64 enabled. A malformed ICMPv6 packet sent to the device can crash and restart the srxpfe packet forwarding engine.
Following Juniper's disclosure of CVE-2026-33785 on 2026-04-08, multiple CERT organizations, including Saudi NCA, Hong Kong CERT, and Norway's JustisCERT, issued urgent alerts recommending immediate patching. Their notices amplified the severity of the MX authorization flaw.
On 2026-04-08, Juniper fixed CVE-2026-33785 in versions 24.4R2-S3, 25.2R2, and 25.4R1. Releases prior to 24.4 were not affected because the vulnerable functionality was introduced in the 24.4 train.
On 2026-04-08, Juniper disclosed CVE-2026-33785, a high-severity missing authorization vulnerability in Junos OS on MX Series routers. The flaw allows any locally authenticated user to execute privileged request csds management commands and, in JDM or CSDS deployments, potentially compromise managed infrastructure behind the router.
When disclosing CVE-2026-33778, Juniper SIRT stated that no malicious exploitation had been observed in the wild, though the issue had been discovered during production usage. This indicated real-world traffic could trigger the crash condition even without confirmed attacks.
On 2026-04-08, Juniper issued security bulletin JSA107868 to fix CVE-2026-33778, a high-severity denial-of-service flaw affecting SRX and MX devices providing IPsec VPN services. A malformed initial ISAKMP packet can crash the kmd or iked daemon and prevent tunnel establishment or rekeying.
On 2026-04-08, Juniper patched CVE-2026-21916, a local privilege escalation flaw in the Junos OS CLI caused by improper symlink handling during configuration commits. The issue allows a low-privileged authenticated user to gain root access when another user performs a commit.
Juniper documented CVE-2025-60004 in advisory JSA103165, describing a critical denial-of-service vulnerability in Junos OS and Junos OS Evolved where malformed BGP EVPN updates can crash the routing protocol daemon. The flaw affects multiple 23.4, 24.2, and 24.4 release trains.
Juniper published a security bulletin and remediation guidance for CVE-2025-59964, a high-severity denial-of-service vulnerability in the SRX4700 Packet Forwarding Engine that can be triggered when forwarding-options sampling is enabled. Repeated traffic can keep the Flexible PIC Concentrator in a crash loop.
Juniper released software updates for CVE-2025-52980, a denial-of-service vulnerability in SRX300 Series devices where crafted BGP UPDATE messages can crash the routing protocol daemon. The issue requires network adjacency and an established BGP session.
Juniper released fixed versions for CVE-2025-52946, a critical use-after-free vulnerability in Junos OS and Junos OS Evolved that can crash the routing protocol daemon via malformed BGP updates when BGP traceoptions are enabled. Administrators were advised to upgrade immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
supportportal.juniper.net
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.