CVE-2026-33784Patch(juniper / virtual_lightweight_collector)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch juniper virtual_lightweight_collector systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-1393

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • virtual_lightweight_collector

Threat summary

  • Patch or workaround signal is available
  • 15 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 14 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 7 mentions (2026-04-10); latest day: 1
  • 15 total mentions across 4 days

Affected systems

Vendors
Products
virtual_lightweight_collector

Deep dive

Activity timeline15 mentions / 4d
02457Mentions · 2026-04-09: 4Mentions · 2026-04-10: 7Mentions · 2026-04-11: 3Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-09: 2Patch / Workaround · 2026-04-10: 5Patch / Workaround · 2026-04-11: 2Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-09: 4Technical Details · 2026-04-10: 6Technical Details · 2026-04-11: 3Technical Details · 2026-04-16: 104-0904-1004-1104-16
Signal classification2 categories
Patch
960.0%
Disclosure
640.0%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-04-094
Disclosure3Patch1
2026-04-107
Disclosure2Patch5
2026-04-113
Disclosure1Patch2
2026-04-161
Patch1
Full discourse15 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Two Critical vulnerabilities in #Juniper CTP OS & JSI. CVE-2026-33771 & CVE-2026-33784 CVSS: 9.1-9.3. Administrator set password requirements are not enforced on users and changing the default superuser password is not enforced on installation. #Patch #Patch #Patch

    Post summary

    The post alerts about two critical Juniper CVEs, provides basic technical details such as CVSS scores, but does not supply a PoC, exploit, or patch details.

    01002360
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Juniper Support Insights の脆弱性 CVE-2026-33784 が FIX:デフォルト認証情報の残存 https://iototsecnews.jp/2026/04/10/juniper-networks-default-credential-vulnerability-allows-unauthorized-full-access/ この問題の原因は、Juniper Networks の vLWC ソフトウェアにおいて、管理者アカウントの初期パスワードが設定された状態で提供され、その変更を強制する仕組みが欠落していたことにあります。そのため、ネットワーク経由でアクセス可能な攻撃者が、既知のデフォルト認証情報を用いるだけで、誰でも簡単にデバイスの完全な制御を奪取できる状態になっています。対策としては、提供されているバージョン 3.0.94 以降への速やかなアップデート、あるいは手動でのパスワード変更が不可欠です。 #CVE202633784 #Juniper #SupportInsights #Vulnerability

    Post summary

    Juniper vLWC software shipped with default credentials that were not forced to change, enabling full device takeover; users must update to v3.0.94 or manually change passwords to remediate.

    01000253
    484 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Juniper Networks issued patches for nearly 36 vulnerabilities in Junos OS, vLWC, and more. Top flaw CVE-2026-33784 exposes a default high-privilege password in Support Insights vLWC. #JuniperFix #NetworkSecurity #USA https://ift.tt/uaHFJsw

    Post summary

    Juniper Networks announced patches for 36 vulnerabilities, including CVE-2026‑33784 which involves a default high‑privilege password in Support Insights vLWC.

    00010155
    3.9K followersView on X
  • CyberTech Insights@CyberTech_In
    Patch

    Juniper Networks flaw (CVE-2026-33784, CVSS 9.8) allows full device takeover via default credentials. Update immediately and remove default passwords. 𝐑𝐞𝐚𝐝 𝐅𝐮𝐥𝐥 𝐒𝐭𝐨𝐫𝐲 : https://cybertechnologyinsights.com/cybersecurity/juniper-default-password-flaw-risks-full-device-takeover/ #CyberSecurity #Juniper #Vulnerability #ThreatAlert https://t.co/c6QXOmM33H

    Post summary

    The CVE-2026-33784 flaw allows full device takeover through default passwords; users are urged to immediately update firmware and remove default credentials.

    00010157
    12 followersView on X
  • dbugs@ptdbugs
    Patch

    JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access CVE: CVE-2026-33784 PT ID: PT-2026-31803 Vendor: Juniper networks Product: JSI LWC CVSS: 9.8 Credits: n/a Description: A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-33784 • https://kb.juniper.net/JSA107871 #dbugs_vuln

    Post summary

    The post describes a high‑severity default‑password vulnerability in Juniper’s JSI Virtual Lightweight Collector and links to a vendor advisory that provides a patch, but no PoC or active exploitation evidence is offered.

    00010156
    788 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33784 A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-bas… https://www.cve.org/CVERecord?id=CVE-2026-33784

    Post summary

    The statement announces CVE‑2026‑33784, a default‑password vulnerability in Juniper Networks’ Virtual Lightweight Collector that allows unauthenticated access. No PoC, exploit, patch, or active exploitation is mentioned.

    00010149
    57.0K followersView on X
  • Riskigy@riskigy
    Patch

    Juniper Networks Patches Dozens of Junos OS Vulnerabilities. A critical-severity flaw could be exploited remotely, without authentication, to take over a vulnerable device. The most severe of the flaws is CVE-2026-33784 (CVSS score of 9.8). https://www.securityweek.com/juniper-networks-patches-dozens-of-junos-os-vulnerabilities/ https://t.co/3iZfqvttnf

    Post summary

    Juniper Networks has released patches for multiple Junos OS vulnerabilities, including a critical flaw (CVE-2026-33784) with a CVSS score of 9.8 that allows remote, unauthenticated takeover of devices.

    00000201
    313 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    Juniper Networks Patches Dozens of Junos OS Vulnerabilities - SecurityWeek https://www.securityweek.com/juniper-networks-patches-dozens-of-junos-os-vulnerabilities/ "CVE-2026-33784 (CVSS score of 9.8), a default password in the Support Insights (JSI) Virtual Lightweight Collector (vLWC) that could be exploited remotely …"

    Post summary

    The text announces Juniper Networks issuing patches for a critical default‑password vulnerability (CVE‑2026‑33784) but provides no exploit evidence or mitigation steps beyond the patch.

    00000264
    3.4K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【Juniper JSI vLWC、初期高権限パスワード問題が重大欠陥化】 JuniperのCVE-2026-33784は、vLWCで初期高権限パスワード変更が強制されないことに起因する問題。未認証の遠隔攻撃者に実質的な機器掌握の余地を与えます。 “脆弱なコード”だけでなく“残る初期設定”も同じくらい危険です。 #Juniper #CVE202633784 #DefaultPassword #NetworkSecurity #SOC https://supportportal.juniper.net/s/article/2026-04-Security-Bulletin-vLWC-Default-password-is-not-required-to-be-changed-which-allows-unauthorized-high-privileged-access-CVE-2026-33784

    Post summary

    The tweet announces CVE-2026-33784, describing how Juniper JSI vLWC’s default high‑privilege password can remain unchanged, allowing unauthenticated remote attackers to gain high‑level access.

    00000349
    3.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Juniper JSI LWC (CVE-2026-33784) https://vuldb.com/vuln/356700

    Post summary

    A new vulnerability (CVE-2026-33784) affecting Juniper JSI LWC has been added to the vuldb.com database, with no additional technical details or exploitation information provided.

    00000182
    2.1K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Juniper alerts CVE-2026-33784 in Support Insights vLWC lets unauthenticated attackers use default password for full device control, fixed in release 3.0.94. https://threatcluster.io/cluster/juniper-networks-default-credential-vulnerability-exposes-de-218cf7dd

    Post summary

    Juniper alerts a default‑credential vulnerability (CVE‑2026‑33784) that allows unauthenticated full device control; a patch is available in release 3.0.94.

    00000105
    132 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    CVSS 9.3 Juniper vulnerability could allow attackers full admin control. Info, incl. fix info, at vulnerability alert service, SecAlerts: CVE-2026-33784: https://secalerts.co/vulnerability/CVE-2026-33784 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE202633784 #Juniper https://t.co/rruRBslTZE

    Post summary

    A high‑severity Juniper vulnerability (CVE‑2026‑33784, CVSS 9.3) is announced, noting it could grant full administrative control, and directs users to a vulnerability alert service that includes fix information.

    00000169
    803 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33784: CRITICAL] Critical vulnerability in Juniper Networks' vLWC allows unauthorized access due to default password. Ensure vLWC versions are at 3.0.94 or newer to mitigate this security risk.#cve,CVE-2026-33784,#cybersecurity https://cvefind.com/CVE-2026-33784

    Post summary

    Juniper Networks’ vLWC suffers a critical default‑password vulnerability; upgrading to version 3.0.94 or newer resolves the issue.

    0000059
    619 followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-33784 | Juniper Networks JSI LWC | Vulnerability Description A use of default password vulnerability in Juniper Networks JSI Virtual Lightweight Collector (vLWC) allows unauth network-based attackers full control by logging in with the unchanged high-privileged initial password, which is not enforced to be changed during provisioning. Severity: Critical Exploitation: Unknown Public PoC: Unknown Patch Available: Unknown Affected Product: Juniper Networks JSI LWC Affected Version: >= 0 and < 3.0.94 Mitigations - The password can be changed in the setup menu of the device, which is described at Configure Network Settings through JSI Shell | Juniper Support Insights | Juniper Networks https://www.juniper.net/documentation/us/en/software/jsi/vlwc-deploy/topics/topic-map/configure-settings-jsi-shell.html Sources Vendor: https://kb.juniper.net/JSA107871

    Post summary

    The post announces a critical default password vulnerability (CVE‑2026‑33784) in Juniper JSI vLWC, notes no known exploitation or PoC, but provides mitigation steps via password change.

    00000110
    7 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33784: JSI Virtual Lightweight Collecto... Juniper shipped enterprise monitoring gear with hardcoded admin creds and zero password enforcement - classic supply ch... https://zerodaysignal.com/vulnerability/CVE-2026-33784 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2026-33784, highlighting that Juniper devices shipped with hardcoded admin credentials and no password enforcement, but offers no PoC, exploit code, or patch details.

    0000072
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjunipervirtual_lightweight_collector---

Explore more