Improper Condition Check in Juniper Networks Junos OS on EX4k and QFX5k Series Platforms
CVE-2026-21910

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
15 January 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-21910?

A vulnerability in the packet forwarding engine of Juniper Networks Junos OS on EX4k and QFX5k Series platforms permits unauthenticated network-adjacent attackers to exploit link flapping in an EVPN-VXLAN configuration. This exploitation can lead to the dropping of inter-VNI traffic when multiple load-balanced next-hop routes are in play, resulting in a Denial of Service (DoS). To recover services, affected devices must be restarted via specific commands. Affected systems include various models which require timely updates for protections against this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Junos OS EX4k Series 0 < 21.4R3-S12

Junos OS EX4k Series 22.2 < 22.2*

Junos OS EX4k Series 22.4 < 22.4R3-S8

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.