Memory Leak Vulnerability in Juniper Networks Junos OS and Junos OS Evolved
CVE-2026-21909
7.1HIGH
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 15 January 2026
Badges
👾 Exploit Exists
What is CVE-2026-21909?
A vulnerability in Juniper Networks' routing protocol daemon (rpd) within Junos OS and Junos OS Evolved allows an unauthenticated attacker positioned as an adjacent IS-IS neighbor to exploit the system by sending specific update packets. This results in a memory leak that can exhaust system resources, leading to a Denial of Service (DoS) condition, which can disrupt normal network operations. It is crucial for users to regularly monitor memory usage to mitigate the impact of this vulnerability.
Affected Version(s)
Junos OS 23.2 < 23.2R2
Junos OS 23.4 < 23.4R1-S2, 23.4R2
Junos OS 24.1 < 24.1R2