CVE-2026-33781Disclosure(juniper / ex4000)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS). On EX4k, and QFX5k platforms configured as service-provider edge devices, if L2PT is enabled on the UNI and VSTP is enabled on NNI in VXLAN scenarios, receiving VSTP BPDUs on UNI leads to packet buffer allocation failures, resulting in the device to not pass traffic anymore until it is manually recovered with a restart.This issue affects Junos OS: * 24.4 releases before 24.4R2, * 25.2 releases before 25.2R1-S1, 25.2R2. This issue does not affect Junos OS releases before 24.4R1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ex4000
  • ex4100
  • ex4100-f
  • ex4100-h

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ex4000ex4100ex4100-fex4100-hex4300ex4400ex4600ex4650junosqfx5110

3 versions affected across 19 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-09: 1Technical Details · 2026-04-09: 104-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-33781 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series… https://www.cve.org/CVERecord?id=CVE-2026-33781

    Post summary

    The text announces CVE‑2026‑33781, describing an improper check vulnerability in Juniper’s packet forwarding engine on EX and QFX series, and links to the official CVE record.

    00000139
    57.0K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
HWjuniperex4000---
HWjuniperex4100---
HWjuniperex4100-f---
HWjuniperex4100-h---
HWjuniperex4300---
HWjuniperex4400---
HWjuniperex4600---
HWjuniperex4650---
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos25.2--
OSjuniperjunos25.2--
OSjuniperjunos25.2--
HWjuniperqfx5110---
HWjuniperqfx5120---
HWjuniperqfx5130---
HWjuniperqfx5200---
HWjuniperqfx5210---
HWjuniperqfx5220---
HWjuniperqfx5230-64cd---
HWjuniperqfx5240---
HWjuniperqfx5241---
HWjuniperqfx5700---

Explore more