CVE-2026-21902Disclosure(juniper / junos_os_evolved)

HIGHCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 20 mentions and remains active

Immediate actions

  • Patch juniper junos_os_evolved systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • junos_os_evolved
  • ptx10001-36mr
  • ptx10002-36qdd
  • ptx10003

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 64 mentions across 17 observed days

What's happening

  • Active exploitation reported across 6 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 27 signals
  • Technical details provided in 49 signals
  • Disclosure: 25 classified signals
  • General: 8 classified signals
  • Peaked 14d ago at 20 mentions (2026-02-27); latest day: 1
  • 64 total mentions across 17 days

Affected systems

Vendors
Products
junos_os_evolvedptx10001-36mrptx10002-36qddptx10003ptx10004ptx10008ptx10016

2 versions affected across 7 products

Deep dive

Activity timeline64 mentions / 17d
05101520Mentions · 2026-02-25: 3Mentions · 2026-02-26: 6Mentions · 2026-02-27: 20Mentions · 2026-02-28: 7Mentions · 2026-03-01: 1Mentions · 2026-03-02: 1Mentions · 2026-03-03: 10Mentions · 2026-03-04: 4Mentions · 2026-03-05: 3Mentions · 2026-03-11: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-23: 1Mentions · 2026-04-04: 1Mentions · 2026-04-11: 1Mentions · 2026-05-31: 2Mentions · 2026-06-26: 1PoC Mentioned / Linked · 2026-02-27: 3PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-03-16: 1Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-05-31: 2Patch / Workaround · 2026-02-26: 3Patch / Workaround · 2026-02-27: 12Patch / Workaround · 2026-02-28: 3Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-04: 3Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 5Technical Details · 2026-02-27: 19Technical Details · 2026-02-28: 6Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 6Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-11: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-26: 102-2502-2602-2702-2803-0103-0203-0303-0403-0503-1103-1603-1703-2304-0404-1105-3106-26
Signal classification5 categories
Disclosure
2539.1%
Patch
2335.9%
General
812.5%
Active Exploitation
69.4%
PoC
23.1%
Referenced assets56 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-253
Disclosure3
2026-02-266
Disclosure3Patch3
2026-02-2720
Active Exploitation1Disclosure7Patch12
2026-02-287
Active Exploitation1Disclosure3Patch3
2026-03-011
Patch1
2026-03-021
Patch1
2026-03-0310
Disclosure4General4Patch1PoC1
2026-03-044
Disclosure3PoC1
2026-03-053
Disclosure1General2
2026-03-111
General1
2026-03-161
Disclosure1
2026-03-171
Patch1
2026-03-231
Active Exploitation1
2026-04-041
General1
2026-04-111
Active Exploitation1
2026-05-312
Active Exploitation2
2026-06-261
Patch1
Full discourse20 posts
  • watchTowr@watchtowrcyber
    General

    Can you feel it too? Join us today for our analysis of Juniper's recent pre-auth RCE - CVE-2026-21902 - affecting a very specific set of devices. Curious? https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/

    Post summary

    The post references Juniper's pre‑auth RCE CVE‑2026‑21902, noting its technical nature but providing no PoC, exploit, patch, or active exploitation details.

    12921003114.6K
    11.0K followersView on X
  • McCaulay@_mccaulay
    Disclosure

    Juniper Junos Evolved RCE CVE-2026-21902 https://t.co/KWMvk4zagN

    Post summary

    A new remote code execution vulnerability (CVE-2026-21902) in Juniper Junos Evolved has been disclosed, with a link to further details.

    111050126.6K
    4.0K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Juniper Networks warns of a critical 9.8 CVSS root vulnerability (CVE-2026-21902) in PTX Series routers. Unauthenticated attackers can gain complete control. #JuniperNetworks #JunosOS #CyberSecurity #CVE #NetworkSecurity #InfoSec #RCE #RouterSecurity https://securityonline.info/critical-flaw-in-juniper-ptx-routers-unauthenticated-root-access-discovered/

    Post summary

    Juniper Networks has disclosed a critical root vulnerability (CVE-2026-21902) in PTX Series routers, allowing unauthenticated attackers to gain full control.

    131114826
    10.4K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) - watchTowr Labs https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/

    Post summary

    The text announces a new RCE vulnerability in Junos OS Evolved (CVE-2026-21902) as reported by watchTowr Labs.

    00015798
    32.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Juniper PTX の脆弱性 CVE-2026-21902 が FIX:ルーター制御の完全な奪取 https://iototsecnews.jp/2026/02/27/juniper-networks-ptx-vulnerability-enables-full-router-takeover/ Juniper Networks は、PTX シリーズ向け Junos OS Evolved に存在する、認証不要で root 権限を奪取され得る、きわめて深刻な脆弱性 CVE-2026-21902 (CVSS4.0:9.3) を公開しました。この脆弱性は、デバイスの異常検知を担う On-Box Anomaly 検出フレームワークの設定ミスに起因します。本来は、内部プロセス専用であるべきサービスが外部ポートに露出することで、リモートの攻撃者に対して、任意のコードの root 権限での実行を許すものとなります。ご利用のチームは、ご注意ください。 #CVE202621902 #Juniper #PTX #Vulnerability

    Post summary

    Juniper Networks disclosed CVE-2026-21902, a high‑severity (CVSS 9.3) root‑takeover vulnerability caused by an exposed service lacking authentication.

    02000168
    483 followersView on X
  • David@davidsheyi
    General

    4/ Junos OS Evolved vulnerability (CVE-2026-21902) reminds us to prioritize security in design. Architects, take note: security should be felt, not just seen. #Blockchain #Security

    Post summary

    The tweet merely references CVE-2026-21902 in Junos OS Evolved and urges architects to prioritize security design, without providing technical details, exploits, patches, or active exploitation evidence.

    1001029
    556 followersView on X
  • Nicolas Krassas@Dinosn
    General

    Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/

    Post summary

    The text references a Junos OS Evolved CVE-2026-21902 RCE vulnerability but provides no further details or actionable information.

    000201.1K
    152.1K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    تحذير: ثغرة خطيرة في أجهزة Juniper PTX اكتشفت ثغرة حرجة CVE-2026-21902 في أجهزة Juniper PTX Series. تسمح هذه الثغرة لأي مهاجم غير مصادق بالوصول الكامل بصلاحيات Root عبر طلب شبكة واحد. يؤدي استغلالها إلى سيطرة كاملة على الجهاز دون الحاجة لأي معلومات مصادقة. 🔗 https://thecyberthrone.in/2026/02/28/cve-2026-21902-juniper-ptx-one-packet-to-root-vulnerability/ #الأمن_السيبراني #Juniper #Vulnerability #CVE

    Post summary

    The post alerts readers to CVE-2026-21902, a critical Juniper PTX vulnerability that permits unauthenticated attackers to gain root via a single packet, but it offers no exploit code, patch, or active exploitation evidence.

    00020282
    3.3K followersView on X
  • Dr.Mashari@GMashari
    Patch

    📌 ثغرة أمنية في أجهزة Juniper Networks PTX تتيح السيطرة الكاملة على الموجّه (Router) 🛡️ الفئة: ثغرة 📝 الملخص: أصدرت شركة Juniper Networks نشرة أمنية طارئة لمعالجة ثغرة حرجة (CVE-2026-21902) في نظام التشغيل Junos OS Evolved، والتي تستهدف تحديداً منصات PTX Series. تكمن خطورة هذه الثغرة في قدرتها على تمكين المهاجمين من فرض سيطرة كاملة على أجهزة التوجيه المتأثرة، مما يهدد استقرار وأمن البنية التحتية للشبكة. نظراً لحرج الموقف، تم إصدار التصحيح الأمني خارج الدورة المعتادة للتحديثات لضمان الاستجابة السريعة للمخاطر السيبرانية المحتملة. يُنصح بـ المسارعة في تطبيق التحديثات الأمنية الصادرة عن الشركة المصنعة وتدقيق سجلات الوصول إلى الأجهزة المتأثرة. 📍 تفاصيل فنية: 🎯 الهدف: منصات PTX Series العاملة بنظام Junos OS Evolved. 🧠 التقنية المستخدمة: استغلال ثغرة حرجة تتيح السيطرة الكاملة (Full Takeover). 🚨 الإجراء المتخذ: إصدار نشرة أمنية وتصحيحات برمجية خارج الجدول الزمني المعتاد. 🛑 التوصيات الأمنية: التحديث الفوري للأنظمة المتأثرة لدرء مخاطر الاستغلال النشط. 🗓️ تاريخ النشر: 27/02/2026 🔗 للمزيد: https://cybersecuritynews.com/juniper-networks-ptx-vulnerability/

    Post summary

    Juniper Networks issued an emergency patch for CVE‑2026‑21902 affecting PTX Series routers, allowing full takeover; users are urged to apply the update immediately.

    00020116
    9.2K followersView on X
  • Zyberwalls@ZyberWallS
    Active Exploitation

    CVE-2026-21902: The "Ghost Packet" is hitting Juniper PTX backbones. One malformed packet = Instant Root Access. No login, no MFA, just total infrastructure takeover. Full technical breakdown & the "Back-Door" glitch: 🔗 https://www.zyberwalls.com/2026/02/juniper-ptx-root-exploit-cve-2026-21902.html #Juniper #Infosec #RootAccess https://t.co/4Xa8pOHMou

    Post summary

    The post asserts that CVE‑2026‑21902 is being actively exploited via malformed packets, granting instant root access to Juniper PTX backbones, and directs readers to a technical breakdown link for further details.

    0101067
    7 followersView on X
  • Zyberwalls@ZyberWallS
    Disclosure

    Attackers aren’t chasing laptops anymore. CVE-2026-21902 → Juniper PTX → Unauthenticated root RCE. This is internet backbone exposure. Full analysis: https://www.zyberwalls.com/2026/02/juniper-ptx-root-exploit-cve-2026-21902.html #NetworkSecurity #CVE #ThreatIntel #CyberAttack @CISACyber https://t.co/iHO5xvpJKb

    Post summary

    The post announces a new CVE (CVE-2026-21902) affecting Juniper PTX, highlighting an unauthenticated root remote code execution vulnerability, with a link to a detailed analysis.

    0101079
    7 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical unauthenticated vulnerability in #Junos OS Evolved. CVE-2026-21902 CVSS: 9.3. This vulnerability can lead to unauthenticated #RCE! https://ccb.belgium.be/advisories/warning-critical-unauthenticated-rce-vulnerability-junos-os-evolved-patch-immediately #Patch #Patch #Patch

    Post summary

    Critical unauthenticated RCE vulnerability in Junos OS Evolved (CVE-2026-21902, CVSS 9.3) is highlighted, with an urgent call to apply patches immediately.

    02000338
    7.2K followersView on X
  • Cyber Toolkit@Cyber_Toolkit
    Patch

    CRITICAL SECURITY ALERT🚨 A critical vulnerability CVE-2026-21902 has been identified in Junos OS Evolved on Juniper PTX Series routers. Juniper are advising immediate patching. https://supportportal.juniper.net/s/article/2026-02-Out-of-Cycle-Security-Bulletin-Junos-OS-Evolved-PTX-Series-A-vulnerability-allows-a-unauthenticated-network-based-attacker-to-execute-code-as-root-CVE-2026-21902 https://t.co/D5jSAv7yHZ

    Post summary

    Juniper has identified CVE‑2026‑21902 in Junos OS Evolved, advising immediate patching to prevent unauthenticated attackers from executing code as root.

    0101053
    3 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Juniper Junos OS Evolved (CVE-2026-21902) https://vuldb.com/?id.347826

    Post summary

    A new critical vulnerability (CVE-2026-21902) has been identified in Juniper Junos OS Evolved, with a reference link provided for further details.

    00101162
    2.1K followersView on X
  • 王俊 ضاري@dari99u
    Patch

    لا تزال ثغرة CVE-2026-21902 من أهم الثغرات لمهندسي مزودي الخدمة (Service Provider)، إذ تؤثر على بعض أجهزة PTX العاملة بـ Junos OS Evolved، وقد تسمح بتنفيذ تعليمات برمجية عن بُعد بدون مصادقة في الإصدارات المتأثرة. https://supportportal.juniper.net/s/article/2026-02-Out-of-Cycle-Security-Bulletin-Junos-OS-Evolved-PTX-Series-A-vulnerability-allows-a-unauthenticated-network-based-attacker-to-execute-code-as-root-CVE-2026-21902?utm_source=chatgpt.com

    Post summary

    The CVE-2026-21902 vulnerability allows unauthenticated code execution on Junos OS Evolved PTX devices; no PoC or exploitation evidence is presented, but a vendor advisory link implies a patch is available.

    0001099
    2.8K followersView on X
  • Divinmentis@Divinmentis
    Active Exploitation

    🔴🌐 Zero credentials, full root on ISP backbone routers. CVE-2026-21902 in Juniper PTX Series exposes an internal port externally by default, granting admin access to any network attacker. Nation-states hit Juniper twice in 2025. This flaw is built for silent pre-positioning at network core. #CyberSecurity #Juniper

    Post summary

    The post reports that CVE-2026-21902 in Juniper PTX Series is actively exploited by nation‑states, exposing an internal port externally by default, but it lacks PoC details, exploit code, or patch information.

    10000151
    15 followersView on X
  • dbugs@ptdbugs
    Disclosure

    RCE in Junos OS Evolved (PTX Series) watchTowr researchers have described a vulnerability CVE-2026-21902 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-21964?fts%5Bvalue%5D=CVE-2026-21902) in Juniper Junos OS Evolved affecting PTX-series devices. The flaw stems from an incorrect permission assignment for critical resource, allowing a remote attacker to execute arbitrary code on the target system. Exploitation requires network access to the vulnerable service but does not require elevated privileges. Successful exploitation grants the attacker command execution capabilities with root privileges. The issue is limited to PTX platforms used in backbone and data center networks where Junos OS Evolved serves as the base operating environment. 📎 Article: https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/ #dbugs_attacks

    Post summary

    A remote code execution flaw (CVE‑2026‑21902) in Juniper Junos OS Evolved on PTX devices stems from incorrect permission handling, allowing root command execution; a PoC link is provided, but no patch, active exploitation, or false positive claim is mentioned.

    00010138
    612 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2026-22719 3 - CVE-2026-25611 4 - CVE-2025-38617 5 - CVE-2026-21902 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top trending CVEs without providing any technical or operational details.

    00010232
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    PoC

    『the On-Box Anomaly Detection Framework is a REST API listening on port 8160/TCP, built in Python, and of course, running as root』 Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/

    Post summary

    A blog post announces a RCE vulnerability (CVE-2026-21902) in Junos OS Evolved, with a link that likely contains a PoC, but no active exploitation or patch details are mentioned.

    00010428
    6.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    Juniper、PTX ルーターに致命的な脆弱性(CVE-2026-21902) https://rocket-boys.co.jp/security-measures-lab/juniper-ptx-router-critical-vulnerability-cve-2026-21902/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The text announces a critical vulnerability in Juniper PTX routers (CVE-2026-21902) but provides no further details.

    01000138
    323 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSjuniperjunos_os_evolved25.4--
HWjuniperptx10001-36mr---
HWjuniperptx10002-36qdd---
HWjuniperptx10003---
HWjuniperptx10004---
HWjuniperptx10008---
HWjuniperptx10016---

Explore more