---
title: "Security Bulletin: Juniper Junos OS Evolved (PTX Series)"
description: "CVE-2026-21902: Critical remote code execution vulnerability in Juniper Junos OS Evolved (PTX Series) requires immediate patching."
---

[Cybersecurity Blog | RedLegg ](https://www.redlegg.com/blog)

# [Security Bulletin: Juniper Junos OS Evolved (PTX Series)](https://www.redlegg.com/blog/security-bulletin-juniper-junos-os-evolved-ptx-series-022626)

 Written by [RedLegg's Cyber Threat Intelligence Team](https://www.redlegg.com/blog/author/redleggs-cyber-threat-intelligence-team) | 2/26/26 9:51 PM

About:

CVE‑2026‑21902: A critical remote code execution vulnerability affects Juniper Junos OS Evolved on PTX Series routers, allowing unauthenticated attackers to execute code as root via an externally exposed anomaly‑detection service. While no active exploitation has been reported, Juniper has released fixed versions, and immediate patching is strongly recommended. Organizations unable to upgrade should restrict access to the affected service and consider disabling the anomaly‑detection feature as a temporary mitigation.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.

## VULNERABILITIES

## Unauthenticated Remote Code Execution as Root in Juniper Junos OS Evolved (PTX Series)

**CVSS Score:** **9.8 (Critical, CVSS v3.1)   
****Identifier: CVE-2026-21902  ****  
**PoC or Exploitation:   
Juniper has stated it was not aware of active malicious exploitation at the time of disclosure.  

Update / Patch: This vulnerability affects Junos OS Evolved on PTX Series routers only. Standard (non-Evolved) Junos OS is not affected.

Affected versions include:   
Junos OS Evolved 25.4 releases prior to 25.4R1-S1-EVO and 25.4R2-EVO

Not affected:   
Junos OS Evolved versions earlier than 25.4R1-EVO   
Junos OS (non-Evolved)   
Fixed versions reported by Juniper and public advisories include:   
25.4R1-S1-EVO   
25.4R2-EVO   
26.2R1-EVO

Primary Juniper advisory reference:   
[https://kb.juniper.net/JSA107128](https://kb.juniper.net/JSA107128?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8_VihzCglPLurFit2KD28TBPcioQ5ez93lCMKjk3dE7gfQ_28PFcBzyMZ04kmszYqP9lCv)<https://kb.juniper.net/JSA107128?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8_VihzCglPLurFit2KD28TBPcioQ5ez93lCMKjk3dE7gfQ_28PFcBzyMZ04kmszYqP9lCv><https://kb.juniper.net/JSA107128?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8_VihzCglPLurFit2KD28TBPcioQ5ez93lCMKjk3dE7gfQ_28PFcBzyMZ04kmszYqP9lCv><https://kb.juniper.net/JSA107128?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8_VihzCglPLurFit2KD28TBPcioQ5ez93lCMKjk3dE7gfQ_28PFcBzyMZ04kmszYqP9lCv>

Description: CVE-2026-21902 is an incorrect permission assignment vulnerability in the On-Box Anomaly Detection framework in Juniper Junos OS Evolved on PTX Series routers. The affected service is intended to be accessible only by internal processes over an internal routing instance, but is reachable via an externally exposed port.

**Mitigation Recommendation:** Patch immediately by upgrading to a fixed Junos OS Evolved release appropriate for your PTX deployment.

If patching cannot be performed immediately, restrict access to the vulnerable service using firewall filters or ACLs so it is reachable only from trusted internal networks.

As a temporary mitigation, consider disabling the vulnerable anomaly detection service using Juniper guidance, for example: request pfe anomalies disable.

[View full post](https://www.redlegg.com/blog/security-bulletin-juniper-junos-os-evolved-ptx-series-022626)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "RedLegg's Cyber Threat Intelligence Team"
  },
  "dateModified" : "2026-02-26T21:51:43.807Z",
  "datePublished" : "2026-02-26T21:51:43Z",
  "headline" : "Emergency Security Bulletin: Juniper Junos OS Evolved (PTX Series)",
  "image" : {
    "@type" : "ImageObject",
    "height" : 630,
    "url" : "https://www.redlegg.com/hubfs/Emergency%20Bulletin%20v2.png",
    "width" : 1200
  },
  "mainEntityOfPage" : "https://www.redlegg.com/blog/security-bulletin-juniper-junos-os-evolved-ptx-series-022626",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/4675768/logo-red-01.png",
      "width" : 419.66666
    },
    "name" : "RedLegg Cybersecurity Blog"
  }
}
```