Critical vulnerability in Junos OS Evolved PTX Series
27 February 2026
Juniper Networks has released security updates addressing a critical vulnerability affecting Junos OS Evolved on PTX Series routers. Users and administrators of affected products are advised to update to the latest version immediately.
Background
Juniper Networks has released security updates addressing a critical vulnerability (CVE-2026-21902) affecting Junos OS Evolved on PTX Series routers. The vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10.
Impact
Successful exploitation of this vulnerability could allow an attacker with network access to the exposed service to execute arbitrary code with root privileges and take full control of the affected device without authentication.
Affected Products
This vulnerability affects Juniper Networks Junos OS Evolved on PTX Series routers version 25.4 prior to 25.4R1-S1-EVO and 25.4R2-EVO.
Older releases may also be affected; however, the vendor does not provide security assessments or patches for versions that have reached end-of-engineering or end-of-life (EoL).
Recommendation
Users and administrators of affected products are advised to update to the latest version immediately.
If immediate patching is not possible, Juniper Networks recommends restricting vulnerable endpoints access to trusted networks only using firewall filters or Access Control Lists (ACLs).
Alternatively, administrators may disable the vulnerable service entirely using the following command:
request pfe anomalies disable
References
