CVE-2026-21910: Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS).
On all EX4k and QFX5k platforms, a link flap in an
EVPN-VXLAN configuration Link Aggregation Group (LAG) results in Inter-VNI traffic dropping when there are multiple load-balanced next-hop routes for the same destination.
This issue is only applicable to systems that support EVPN-VXLAN Virtual Port-Link Aggregation Groups (VPLAG), such as the QFX5110, QFX5120, QFX5200, EX4100, EX4300, EX4400, and EX4650.
Service can only be restored by restarting the affected FPC via the 'request chassis fpc restart slot <slot-number>' command.
This issue affects Junos OS
on EX4k and QFX5k Series:
all versions before 21.4R3-S12, all versions of 22.2 from 22.4 before 22.4R3-S8, from 23.2 before 23.2R2-S5, from 23.4 before 23.4R2-S5, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OSto a version that resolves this vulnerability.Fixed in 21.4R3-S12 - Upgrade
Upgrade
Juniper Networks Junos OSto a version that resolves this vulnerability.Fixed in 22.4R3-S8 - Upgrade
Upgrade
Juniper Networks Junos OSto a version that resolves this vulnerability.Fixed in 23.2R2-S5 - Upgrade
Upgrade
Juniper Networks Junos OSto a version that resolves this vulnerability.Fixed in 23.4R2-S5 - Upgrade
Upgrade
Juniper Networks Junos OSto a version that resolves this vulnerability.Fixed in 24.2R2-S3 - Upgrade
Upgrade
Juniper Networks Junos OSto a version that resolves this vulnerability.Fixed in 24.4R2 - Upgrade
Upgrade
Juniper Networks Junos OSto a version that resolves this vulnerability.Fixed in 25.2R1 - Compensating control
For EX4k and QFX5k platforms in an EVPN-VXLAN configuration (Inter-VNI traffic drop on link flaps), restore Service only by restarting the affected FPC using: 'request chassis fpc restart slot <slot-number>'.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21910?
CVE-2026-21910 is classified as a high-severity vulnerability affecting Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms.
How do I fix CVE-2026-21910?
To mitigate CVE-2026-21910, update your Junos OS to the latest patched version as specified by Juniper Networks.
What systems are affected by CVE-2026-21910?
CVE-2026-21910 affects Junos OS running on EX4k Series and QFX5k Series platforms.
What types of attacks can exploit CVE-2026-21910?
CVE-2026-21910 can be exploited by causing link flaps in an EVPN-VXLAN configuration, leading to Inter-VNI traffic drops.
Is there a workaround for CVE-2026-21910?
Currently, the only effective measure for CVE-2026-21910 is to implement the recommended software updates from Juniper Networks.