logo

Critical Juniper Networks PTX flaw allows full router takeover

ID: f53b6fdf-b566-513e-b4dc-d237ea3b0d7c

STIX ID: report--f53b6fdf-b566-513e-b4dc-d237ea3b0d7c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical vulnerability (CVE-2026-21902) in Junos OS Evolved on PTX Series routers allows unauthenticated remote code execution as root because the On-Box Anomaly Detection framework is exposed on an external port by incorrect permission assignment; affected versions are prior to 25.4R1-S1-EVO and 25.4R2-EVO, with vendor fixes released and recommended mitigations including access restrictions or disabling the service. Juniper reported no known active exploitation at the time of the advisory, and administrators are urged to apply patches or apply ACL/firewall restrictions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.