CVE-2026-21910: Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop

Published Jan 15, 2026
·
Updated

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS).

On all EX4k and QFX5k platforms, a link flap in an

EVPN-VXLAN configuration Link Aggregation Group (LAG) results in Inter-VNI traffic dropping when there are multiple load-balanced next-hop routes for the same destination.

This issue is only applicable to systems that support EVPN-VXLAN Virtual Port-Link Aggregation Groups (VPLAG), such as the QFX5110, QFX5120, QFX5200, EX4100, EX4300, EX4400, and EX4650.

Service can only be restored by restarting the affected FPC via the 'request chassis fpc restart slot <slot-number>' command.

This issue affects Junos OS

on EX4k and QFX5k Series:

all versions before 21.4R3-S12,  all versions of 22.2 from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S5,  from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2.

Affected Software

84 affected components
Juniper Networks Junos OS<21.4R3-S12, =22.2, >=22.4, <22.4R3-S8, >=23.2, <23.2R2-S5, >=23.4, <23.4R2-S5, >=24.2, <24.2R2-S3, >=24.4, <24.4R2
All of the following
Any of the following
Juniper Junos<21.4
Juniper Junos=21.4
Juniper Junos=21.4-r1
Juniper Junos=21.4-r1-s1
Juniper Junos=21.4-r1-s2
Juniper Junos=21.4-r2
Juniper Junos=21.4-r2-s1
Juniper Junos=21.4-r2-s2
Juniper Junos=21.4-r3
Juniper Junos=21.4-r3-s1
Juniper Junos=21.4-r3-s10
Juniper Junos=21.4-r3-s11
Juniper Junos=21.4-r3-s2
Juniper Junos=21.4-r3-s3
Juniper Junos=21.4-r3-s4
Juniper Junos=21.4-r3-s5
Juniper Junos=21.4-r3-s6
Juniper Junos=21.4-r3-s7
Juniper Junos=21.4-r3-s8
Juniper Junos=21.4-r3-s9
Juniper Junos=22.2
Juniper Junos=22.4
Juniper Junos=22.4-r1
Juniper Junos=22.4-r1-s1
Juniper Junos=22.4-r1-s2
Juniper Junos=22.4-r2
Juniper Junos=22.4-r2-s1
Juniper Junos=22.4-r2-s2
Juniper Junos=22.4-r3
Juniper Junos=22.4-r3-s1
Juniper Junos=22.4-r3-s2
Juniper Junos=22.4-r3-s3
Juniper Junos=22.4-r3-s4
Juniper Junos=22.4-r3-s5
Juniper Junos=22.4-r3-s6
Juniper Junos=22.4-r3-s7
Juniper Junos=23.2
Juniper Junos=23.2-r1
Juniper Junos=23.2-r1-s1
Juniper Junos=23.2-r1-s2
Juniper Junos=23.2-r2
Juniper Junos=23.2-r2-s1
Juniper Junos=23.2-r2-s2
Juniper Junos=23.2-r2-s3
Juniper Junos=23.2-r2-s4
Juniper Junos=23.4
Juniper Junos=23.4-r1
Juniper Junos=23.4-r1-s1
Juniper Junos=23.4-r1-s2
Juniper Junos=23.4-r2
Juniper Junos=23.4-r2-s1
Juniper Junos=23.4-r2-s2
Juniper Junos=23.4-r2-s3
Juniper Junos=23.4-r2-s4
Juniper Junos=24.2
Juniper Junos=24.2-r1
Juniper Junos=24.2-r1-s1
Juniper Junos=24.2-r1-s2
Juniper Junos=24.2-r2
Juniper Junos=24.2-r2-s1
Juniper Junos=24.2-r2-s2
Juniper Junos=24.4
Juniper Junos=24.4-r1
Juniper Junos=24.4-r1-s2
Juniper Junos=24.4-r1-s3
Any of the following
Juniper EX4000
Juniper EX4100
Juniper Ex4100-f
Juniper Ex4100-h
Juniper EX4300
Juniper EX4400
Juniper EX4600
Juniper EX4650
Juniper QFX5110
Juniper QFX5120
Juniper Qfx5130
Juniper QFX5200
Juniper QFX5210
Juniper QFX5220
Juniper Qfx5230-64cd
Juniper Qfx5240
Juniper Qfx5241
Juniper Qfx5700

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS to a version that resolves this vulnerability.

    Fixed in 21.4R3-S12
  2. Upgrade

    Upgrade Juniper Networks Junos OS to a version that resolves this vulnerability.

    Fixed in 22.4R3-S8
  3. Upgrade

    Upgrade Juniper Networks Junos OS to a version that resolves this vulnerability.

    Fixed in 23.2R2-S5
  4. Upgrade

    Upgrade Juniper Networks Junos OS to a version that resolves this vulnerability.

    Fixed in 23.4R2-S5
  5. Upgrade

    Upgrade Juniper Networks Junos OS to a version that resolves this vulnerability.

    Fixed in 24.2R2-S3
  6. Upgrade

    Upgrade Juniper Networks Junos OS to a version that resolves this vulnerability.

    Fixed in 24.4R2
  7. Upgrade

    Upgrade Juniper Networks Junos OS to a version that resolves this vulnerability.

    Fixed in 25.2R1
  8. Compensating control

    For EX4k and QFX5k platforms in an EVPN-VXLAN configuration (Inter-VNI traffic drop on link flaps), restore Service only by restarting the affected FPC using: 'request chassis fpc restart slot <slot-number>'.

Event History

Jan 15, 2026
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-21910?

CVE-2026-21910 is classified as a high-severity vulnerability affecting Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms.

2

How do I fix CVE-2026-21910?

To mitigate CVE-2026-21910, update your Junos OS to the latest patched version as specified by Juniper Networks.

3

What systems are affected by CVE-2026-21910?

CVE-2026-21910 affects Junos OS running on EX4k Series and QFX5k Series platforms.

4

What types of attacks can exploit CVE-2026-21910?

CVE-2026-21910 can be exploited by causing link flaps in an EVPN-VXLAN configuration, leading to Inter-VNI traffic drops.

5

Is there a workaround for CVE-2026-21910?

Currently, the only effective measure for CVE-2026-21910 is to implement the recommended software updates from Juniper Networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203