CVE-2026-21907: Junos Space: TLS/SSL server supports use of static key ciphers (ssl-static-key-ciphers)
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space allows the use of static key ciphers (ssl-static-key-ciphers), reducing the confidentiality of on-path traffic communicated across the connection. These ciphers also do not support Perfect Forward Secrecy (PFS), affecting the long-term confidentiality of encrypted communications.This issue affects all versions of Junos Space before 24.1R5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21907?
CVE-2026-21907 has a high severity due to its vulnerability in the use of static key ciphers in TLS/SSL, compromising data confidentiality.
How do I fix CVE-2026-21907?
To fix CVE-2026-21907, disable the use of static key ciphers in the Junos Space TLS/SSL configuration.
What systems are affected by CVE-2026-21907?
CVE-2026-21907 affects Juniper Networks Junos Space versions up to 24.1R5.
What are the risks associated with CVE-2026-21907?
The risks associated with CVE-2026-21907 include potential data breaches and loss of confidentiality due to the use of broken cryptographic algorithms.
Is there a workaround for CVE-2026-21907?
A workaround for CVE-2026-21907 is to avoid using static key ciphers within the TLS/SSL configuration until a patch can be applied.