# Juniper patches multiple Junos OS vulnerabilities

Published: 2026-07-09 · Severity: medium · Sectors: telecommunications, infrastructure
Canonical: https://vorant.io/reports/8da20337-abe4-5885-8058-52f6d8ae57d6/juniper-patches-multiple-junos-os-vulnerabilities

> ANSSI advisory details numerous vulnerabilities across Juniper Junos OS, Junos OS Evolved, cRPD, CTPView, Junos Space and Network Director, mostly enabling denial of service.

CERT-FR published an advisory summarizing a large batch of vulnerabilities patched by Juniper Networks across its Junos OS, Junos OS Evolved, cRPD, CTPView, Junos Space, and Network Director product lines. The flaws, disclosed via Juniper's July 2026 security bulletins, affect numerous version branches and platform series (MX, SRX, EX, QFX, PTX) and can lead to remote denial of service through process crashes (rpd, flowd, l2ald, iked, fxpc, evo-pfemand), memory leaks, FPC/PFE resets, and in some cases arbitrary code execution or confidentiality breaches. Root causes span malformed BGP/SNMPv3/TCP/SIP packet handling, VPN negotiation failures, SSH configuration issues, and improperly exposed ports.

The advisory lists over 20 CVEs, including a re-flagged legacy libfetch heap-buffer-overflow issue (CVE-2020-7450) affecting Junos OS Evolved. No evidence of active exploitation is indicated in the source; this is a routine vendor patch cycle affecting network infrastructure devices widely used by enterprises and service providers. Affected organizations should prioritize patching based on exposed services (SNMP, VPN, web filtering) and platform criticality, referring to Juniper's individual security bulletins for version-specific fixes.

## Mentioned in this report

- Vulnerabilities: CVE-2020-7450, CVE-2026-21901, CVE-2026-33794, CVE-2026-33799, CVE-2026-33800, CVE-2026-33801, CVE-2026-33802, CVE-2026-33803, CVE-2026-57019, CVE-2026-57020, CVE-2026-57021, CVE-2026-57022, CVE-2026-57023, CVE-2026-57024, CVE-2026-57025, CVE-2026-57026, CVE-2026-57027, CVE-2026-57028, CVE-2026-57029, CVE-2026-57030, CVE-2026-57031, CVE-2026-57032, CVE-2026-57054

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0852

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8da20337-abe4-5885-8058-52f6d8ae57d6/juniper-patches-multiple-junos-os-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
