• News/
  • https://www.bleepingcomputer.com/news/security/critical-juniper-networks-ptx-flaw-allows-full-router-takeover/

Critical Juniper Networks PTX flaw allows full router takeover

BleepingComputer
·
Bill Toulas
·
Published Feb 26, 2026
·
Updated

A critical vulnerability in the Junos OS Evolved network operating system running on PTX Series routers from Juniper Networks could allow an unauthenticated attacker to execute code remotely with root privileges. PTX Series routers are high-performance core and peering routers built for high throughput, low latency, and scale. They are commonly used by internet service providers, telecommunication services, and cloud network applications. The security issue is identified as CVE-2026-21902 and is caused by incorrect permission assignment in the ‘On-Box Anomaly Detection’ framework, which should be exposed to internal processes only over the internal routing interface. However, the glitch allows accessing the framework over an externally exposed port, Juniper Networks explains in a security advisory. Because the service runs as root and is enabled by default, successful exploitation would allow an attacker who is already on the network to take full control of the device without authentication. The issue affects Junos OS Evolved versions before 25.4R1-S1-EVO and 25.4R2-EVO, on PTX Series routers. Older versions may also be impacted, but the vendor does not assess releases that have reached the end-of-engineering or end-of-life (EoL) phase. Versions before 25.4R1-EVO, and standard (non-Evolved) Junos OS versions are not impacted by CVE-2026-21902. Juniper Networks has delivered fixes in versions 25.4R1-S1-EVO, 25.4R2-EVO, and 26.2R1-EVO of the product. Juniper's Security Inciden...

Read full article

Affected Software

1 affected component
Juniper Networks Junos OS Evolved<25.4R1-S1-EVO, <25.4R2-EVO

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Juniper Networks' Junos OS Evolved that allows for full router takeover.

2

What security implications are discussed?

The vulnerability could enable unauthenticated attackers to execute code remotely with root privileges on affected routers.

3

What products or software are affected?

The affected product is Juniper Networks' Junos OS Evolved, specifically on PTX Series routers.

4

What is the severity of the vulnerability mentioned?

The vulnerability is classified as critical due to its potential for remote code execution.

5

What versions of Junos OS Evolved are impacted?

The impacted versions include up to but not including 25.4R1-S1-EVO and 25.4R2-EVO.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203