CVE-2026-21910 Details
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS). On all EX4k and QFX5k platforms, a link flap in an EVPN-VXLAN configuration Link Aggregation Group (LAG) results in Inter-VNI traffic dropping when there are multiple load-balanced next-hop routes for the same destination. This issue is only applicable to systems that support EVPN-VXLAN Virtual Port-Link Aggregation Groups (VPLAG), such as the QFX5110, QFX5120, QFX5200, EX4100, EX4300, EX4400, and EX4650. Service can only be restored by restarting the affected FPC via the 'request chassis fpc restart slot <slot-number>' command. This issue affects Junos OS on EX4k and QFX5k Series: * all versions before 21.4R3-S12, * all versions of 22.2 * from 22.4 before 22.4R3-S8, * from 23.2 before 23.2R2-S5, * from 23.4 before 23.4R2-S5, * from 24.2 before 24.2R2-S3, * from 24.4 before 24.4R2.
A vulnerability has been identified in the packet forwarding engine of Juniper Networks Junos OS, specifically on EX4k Series and QFX5k Series platforms. This vulnerability allows an unauthenticated, network-adjacent attacker to cause a denial-of-service condition by flapping an interface. In systems configured with EVPN-VXLAN Link Aggregation Groups (LAG), this action can disrupt traffic between VXLAN Network Identifiers (VNIs), particularly when multiple load-balanced next-hop routes are available for the same destination. The issue requires a specific configuration to be exploited and can only be resolved by restarting the affected forwarding plane component.
Users can upgrade to Junos OS versions 21.4R3-S12, 22.4R3-S8, 23.2R2-S5, 23.4R2-S5, 24.2R2-S3, 24.4R2, 25.2R1, or any subsequent release. Instructions for upgrading can be found on the Juniper Networks Customer Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA106009 | [email protected] | Vendor Advisory |
| https://supportportal.juniper.net/JSA106009 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 21.4 21.4 - 21.4 r1 21.4 r1-s1 21.4 r1-s2 21.4 r2 21.4 r2-s1 21.4 r2-s2 21.4 r3 21.4 r3-s1 21.4 r3-s10 21.4 r3-s11 21.4 r3-s2 21.4 r3-s3 21.4 r3-s4 21.4 r3-s5 21.4 r3-s6 21.4 r3-s7 21.4 r3-s8 21.4 r3-s9 22.2 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 22.4 r3-s7 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 |
CPE
Remediation
| |
| juniper ex4000 | All versions |
CPE
Remediation
| |
| juniper ex4100 | All versions |
CPE
Remediation
| |
| juniper ex4100-f | All versions |
CPE
Remediation
| |
| juniper ex4100-h | All versions |
CPE
Remediation
| |
| juniper ex4300 | All versions |
CPE
Remediation
| |
| juniper ex4400 | All versions |
CPE
Remediation
| |
| juniper ex4600 | All versions |
CPE
Remediation
| |
| juniper ex4650 | All versions |
CPE
Remediation
| |
| juniper qfx5110 | All versions |
CPE
Remediation
| |
| juniper qfx5120 | All versions |
CPE
Remediation
| |
| juniper qfx5130 | All versions |
CPE
Remediation
| |
| juniper qfx5200 | All versions |
CPE
Remediation
| |
| juniper qfx5210 | All versions |
CPE
Remediation
| |
| juniper qfx5220 | All versions |
CPE
Remediation
| |
| juniper qfx5230-64cd | All versions |
CPE
Remediation
| |
| juniper qfx5240 | All versions |
CPE
Remediation
| |
| juniper qfx5241 | All versions |
CPE
Remediation
| |
| juniper qfx5700 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | Initial Analysis | [email protected] |
| Jan 15, 2026 | New CVE Received | [email protected] |