CVE-2026-33800: Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash

Published Jul 9, 2026
·
Updated

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage.

This issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304.

This issue affects Junos OS on MX Series:

all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S3, 25.2 versions before 25.2R2.

Affected Software

1 affected component
Juniper Networks Junos OS on MX Series<23.2R2-S7, <23.4R2-S8, <24.2R2-S4, <24.4R2-S3, <25.2R2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 23.2R2-S7
  2. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 23.4R2-S8
  3. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 24.2R2-S4
  4. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 24.4R2-S3
  5. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 25.2R2
  6. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 25.4R1

Event History

Jul 9, 2026
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33800?

The severity of CVE-2026-33800 is medium with a CVSS score of 6.5.

2

How does CVE-2026-33800 affect Junos OS on MX Series?

CVE-2026-33800 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS) by exploiting high rates of micro-BFD session flaps.

3

What are the potential impacts of CVE-2026-33800?

The potential impact of CVE-2026-33800 includes the crashing of the FPC, leading to network service disruptions.

4

How can I mitigate CVE-2026-33800?

Mitigation for CVE-2026-33800 involves applying the latest patches and following best practices for network security.

5

Is CVE-2026-33800 exploitable remotely?

No, CVE-2026-33800 requires an adjacent attacker to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203