Juniper Networks vendor intelligence
Juniper Networks Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Juniper Networks products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 11
- Known exploited vulnerabilities affecting Juniper Networks products
- In CISA KEV
- 8
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Juniper Networks KEVs with sensor-observed exploitation activity
The catalog gap matters for Juniper Networks exposure
Three of the eleven exploited Juniper Networks CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 27% of this vendor portfolio.
- 73%
- Covered by CISA
- 27%
- Beyond CISA
- 3
- Product families
Attested Juniper Networks CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-21902
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root |
Junos OS Evolved | High | Beyond CISA | 19 Mar 2026 |
|
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS |
Junos OS | High | Beyond CISA | 07 Mar 2026 |
|
CVE-2022-22242
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web |
Junos OS | High | Beyond CISA | 21 Jul 2025 |
|
CVE-2015-7755
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before... |
ScreenOS | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-1631
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services |
Junos OS | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files |
Junos OS | Confirmed | In CISA | 13 Nov 2023 |
|
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files |
Junos OS | Confirmed | In CISA | 13 Nov 2023 |
|
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files |
Junos OS | Confirmed | In CISA | 13 Nov 2023 |
|
CVE-2023-36845
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable |
Junos OS | Confirmed | In CISA | 13 Nov 2023 |
|
CVE-2023-36844
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables |
Junos OS | Confirmed | In CISA | 13 Nov 2023 |
|
CVE-2025-21590
Junos OS: An local attacker with shell access can execute arbitrary code |
Junos OS | Confirmed | In CISA | 13 Mar 2025 |
No Juniper Networks CVEs match this search or filter.
Showing 11 of 11 Juniper Networks known exploited vulnerabilities.
Recurring weakness patterns
Missing authentication for critical function, php external variable modification, and neutralization account for seven mapped occurrences across this Juniper Networks KEV portfolio.
CWE-306
Missing Authentication for Critical Function
CWE-473
PHP External Variable Modification
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-73
External Control of File Name or Path
CWE-732
Incorrect Permission Assignment for Critical Resource
CWE-653
Improper Isolation or Compartmentalization
CWE-287
Improper Authentication
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.