CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 564

As cited

Copy frozen at (site build).

vulnerabilities

Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)

CVE-2026-21902 is an unauthenticated remote code execution vulnerability in Juniper's Junos OS Evolved on PTX Series routers, caused by incorrect permission assignment in the On-Box Anomaly Detection Framework. The vulnerable service listens on port 8160 and is accessible over the network despite being intended for internal-only access, allowing attackers to execute code as root without authentication. The vulnerability affects Junos OS Evolved 25.4 versions before 25.4R1-S1-EVO and 25.4R2-EVO, with the service enabled by default.

Why it matters: Organizations operating Juniper PTX Series routers with Junos OS Evolved versions 25.4 (excluding 25.4R1-EVO and earlier) should immediately patch to 25.4R1-S1-EVO or later to prevent unauthenticated remote takeover of core network infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)

CVE-2026-21902 is an unauthenticated remote code execution vulnerability in Juniper's Junos OS Evolved on PTX Series routers, caused by incorrect permission assignment in the On-Box Anomaly Detection Framework. The vulnerable service listens on port 8160 and is accessible over the network despite being intended for internal-only access, allowing attackers to execute code as root without authentication. The vulnerability affects Junos OS Evolved 25.4 versions before 25.4R1-S1-EVO and 25.4R2-EVO, with the service enabled by default.

Why it matters: Organizations operating Juniper PTX Series routers with Junos OS Evolved versions 25.4 (excluding 25.4R1-EVO and earlier) should immediately patch to 25.4R1-S1-EVO or later to prevent unauthenticated remote takeover of core network infrastructure.

VendorsJuniper
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary