Threat reportVulnerabilityTL-2026-0269

CVE-2026-21902: Juniper PTX Series Junos OS Evolved Unauthenticated Remote Code Execution as Root via On-Box Anomaly Detection Framework (CVSS 9.8)

criticalPATCHED

CVE-2026-21902 (TL-2026-0269), also tracked as JSA107128, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-22 and last reviewed 2026-07-19. It has no confirmed attribution, affects Juniper Networks Junos OS Evolved, references 1 CVE (CVE-2026-21902), maps to 20 MITRE ATT&CK techniques (T1040, T1046, T1053), and is covered by 9 detection rules and 24 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-0269

Threat ID
TL-2026-0269
Also known as
JSA107128
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
telecommunications, government, financial, healthcare, energy, technology, critical-infrastructure, internet-service-providers, cloud-providers, defense
Target regions
Global
Detection rules
9
Indicators of compromise
24
Updates
2026-07-19 · revalidated 1× · latest source

Malware and tooling in CVE-2026-21902

Malware and tooling: watchTowr-vs-JunosEvolved-CVE-2026-21902

How CVE-2026-21902 works

Critical unauthenticated remote code execution vulnerability in Juniper Networks PTX Series routers running Junos OS Evolved. The On-Box Anomaly Detection Framework exposes a Python REST API on port 8160/TCP bound to all interfaces without authentication, allowing any network-based attacker to execute arbitrary commands as root via crafted API requests. CVSS 9.8 with no user interaction required.

CVE-2026-21902 is a critical pre-authentication remote code execution vulnerability affecting Juniper Networks PTX Series routers running Junos OS Evolved version 25.4R1-EVO. The flaw resides in the On-Box Anomaly Detection Framework, an internal security monitoring service that was inadvertently exposed to external network access due to incorrect default permissions (CWE-276/CWE-732).

The vulnerability stems from a Python-based REST API server (api_server.py) that binds to 0.0.0.0:8160/TCP instead of the localhost interface. This service is part of the On-Box Anomaly Detection Framework and was designed to be reachable only by other internal processes over the internal routing instance. However, the incorrect permission assignment causes the service to listen on all network interfaces, making it accessible to any unauthenticated remote attacker.

The exploitation chain leverages four REST API endpoints that require no authentication:

1. POST /config/command/<name> — Creates a Command definition with type RE-SHELL containing arbitrary shell syntax 2. POST /config/dag/<name> — Defines a DAG (Directed Acyclic Graph) workflow referencing the malicious command 3. POST /config/dag-instance/<name> — Creates a scheduled execution instance with immediate timing 4. POST /config/commit — Validates and persists the configuration, triggering execution

When the schedule_enforcer.py process (running as root) detects the scheduled DAG instance, it retrieves the command definition and passes the attacker-controlled syntax field directly to subprocess.run(command, shell=True), achieving arbitrary command execution with root privileges. The vulnerable code path flows through execute_dag_instance() -> execute_dag() -> run_bfs_on_dag_actions() -> execute_command(), with no input sanitization at any stage.

The service is enabled by default on affected versions without requiring any specific configuration, meaning all PTX Series routers running vulnerable Junos OS Evolved versions are exposed out of the box. Successful exploitation grants complete device control including configuration manipulation (routing tables, BGP sessions, ACLs), traffic interception or redirection, credential and cryptographic key exfiltration, and service disruption via control-plane interference.

Juniper Networks released this as an out-of-cycle emergency security bulletin (JSA107128) on February 25, 2026, indicating the severity and urgency. The watchTowr Labs team published a detailed technical analysis and proof-of-concept on March 3, 2026, demonstrating the full exploitation chain. Multiple government agencies including the Cyber Security Agency of Singapore issued alerts. No confirmed active exploitation in the wild has been reported, though the trivial exploitation complexity and public PoC availability make exploitation highly likely.

MITRE ATT&CK techniques used in TL-2026-0269

credential-access

T1040 Network Sniffing

discovery

T1046 Network Service Discovery; T1082 System Information Discovery

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter

privilege-escalation

T1068 Exploitation for Privilege Escalation

defense-evasion

T1070 Indicator Removal

command-and-control

T1071 Application Layer Protocol

initial-access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

impact

T1489 Service Stop; T1498 Network Denial of Service; T1565 Data Manipulation

Impact

T1495 Firmware Corruption

Persistence

T1505 Server Software Component

persistence

T1543 Create or Modify System Process

Reconnaissance

T1595.001 Active Scanning: Scanning IP Blocks; T1595.002 Active Scanning: Vulnerability Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CVE-2026-21902

  • Juniper Networks — Junos OS Evolved
    Vulnerable versions: 25.4R1-EVO (all builds before 25.4R1-S1-EVO)
    Fixed in: 25.4R1-S1-EVO; 25.4R2-EVO; 26.2R1-EVO
  • Juniper Networks — PTX Series Routers
    Vulnerable versions: All PTX models running vulnerable Junos OS Evolved versions
    Fixed in: PTX models running patched Junos OS Evolved

Remediation for CVE-2026-21902

Patches

  • Junos OS Evolved 25.4R1-S1-EVO (emergency out-of-cycle patch)
  • Junos OS Evolved 25.4R2-EVO
  • Junos OS Evolved 26.2R1-EVO

Immediate actions

  • Block TCP port 8160 at network perimeter via ACLs and firewall filters
  • Restrict management plane access to trusted internal subnets only
  • Disable the vulnerable service using CLI command: request pfe anomalies disable
  • Audit PTX Series router fleet for Junos OS Evolved version 25.4R1-EVO exposure
  • Monitor for unauthorized connections to port 8160/TCP on all PTX Series devices

Workarounds

  • Disable On-Box Anomaly Detection: request pfe anomalies disable
  • Apply firewall filter to block external access to TCP port 8160
  • Restrict management interface access via lo0 filter to trusted hosts only

Longer-term hardening

  • Deploy network segmentation isolating router management interfaces from untrusted networks
  • Implement out-of-band management networks for all critical network infrastructure
  • Deploy network-based IDS/IPS signatures for anomalous HTTP traffic to port 8160
  • Establish automated version compliance monitoring for Juniper infrastructure
  • Review and harden all Juniper device management plane access controls

CVEs associated with CVE-2026-21902

CVE-2026-21902

Weaknesses (CWE) in CVE-2026-21902

CWE-276, CWE-732

Timeline of CVE-2026-21902

  • CVE-2026-21902 published to NVD; Juniper Networks releases out-of-cycle emergency security bulletin JSA107128
  • Threat intelligence reports begin covering the vulnerability; ThreatIntelReport publishes initial technical analysis
  • Juniper confirms patched versions 25.4R1-S1-EVO and 25.4R2-EVO available; workaround via request pfe anomalies disable documented
  • Cyber Security Agency of Singapore issues Alert AL-2026-020; multiple security news outlets publish analyses and risk assessments
  • UpGuard and additional security vendors publish risk assessments and exposure analyses for enterprise customers
  • Vendor and third-party trackers (runZero) clarify the precise vulnerable version boundary: 25.4R1-EVO through versions prior to 25.4R1-S1-EVO, and 25.4R1-S1-EVO through versions prior to 25.4R2-EVO; releases before 25.4R1-EVO confirmed not vulnerable.
  • watchTowr Labs researcher McCaulay Hudson (@_mccaulay) credited as discoverer and author of the technical write-up and public PoC exploit.
  • NVD record last modified with additional details including CVSS 4.0 score of 9.3 and updated CWE/CAPEC references
  • watchTowr Labs publishes detailed technical analysis with full exploitation chain walkthrough and PoC tools on GitHub
  • Purple Ops publishes detailed exploitation guide with step-by-step API request examples and detection recommendations
  • Cyble Research and Intelligence Labs includes CVE-2026-21902 in weekly vulnerability report, confirming ongoing risk assessment
  • As of 2026-05-29, CVE-2026-21902 remains PATCHED: Juniper's out-of-cycle fixes (25.4R1-S1-EVO/25.4R2-EVO) are public, the flaw was vendor-discovered with no confirmed in-the-wild exploitation, and it is not in CISA KEV. A public watchTowr PoC keeps residual risk for unpatched PTX fleets, but no active campaign or actor is reported.

Update history for TL-2026-0269

Sources cited for CVE-2026-21902

Detection coverage for TL-2026-0269

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0269 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats