Warning: Vulnerabilities in Juniper Junos OS allow Denial of Service (CVE-2026
NVD - NVD -
Two vulnerabilities have been identified in Juniper Junos OS that could allow attackers to trigger a complete Denial of Service (DoS) condition on affected devices.
Successful exploitation of either vulnerability can highly impact the availability of network devices and may disrupt critical services.
CVE-2026-33782 (CVSS 8.7), is a Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, that allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete DoS.
CVE-2026-33783 (CVSS 7.1), a Function Call with Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series, allows a network-based, authenticated attacker with low privileges to cause a complete DoS.
If SRTE policy tunnels are provisioned via PCEP, and gRPC is used to monitor traffic in these tunnels, evo-aftmand crashes and doesn't restart which leads to a complete and persistent service impact. The system must be manually restarted to recover. The issue is seen only when the Originator ASN field in PCEP contains a value larger than 65,535 (32-bit ASN). The issue is not reproducible when SRTE policy tunnels are statically configured.
Patch The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable instances with the highest priority after thorough testing.
The following software releases have been updated to resolve these issues:
Monitor/Detect The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion
In case of an intrusion, you can report an incident via .
While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
