Threat reportVulnerabilityTL-2026-0269
CVE-2026-21902: Juniper PTX Series Junos OS Evolved Unauthenticated Remote Code Execution as Root via On-Box Anomaly Detection Framework (CVSS 9.8)
CVE-2026-21902 (TL-2026-0269), also tracked as JSA107128, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-22 and last reviewed 2026-07-19. It has no confirmed attribution, affects Juniper Networks Junos OS Evolved, references 1 CVE (CVE-2026-21902), maps to 20 MITRE ATT&CK techniques (T1040, T1046, T1053), and is covered by 9 detection rules and 24 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-0269
- Threat ID
- TL-2026-0269
- Also known as
- JSA107128
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- telecommunications, government, financial, healthcare, energy, technology, critical-infrastructure, internet-service-providers, cloud-providers, defense
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
- Updates
- 2026-07-19 · revalidated 1× · latest source
Malware and tooling in CVE-2026-21902
Malware and tooling: watchTowr-vs-JunosEvolved-CVE-2026-21902
How CVE-2026-21902 works
Critical unauthenticated remote code execution vulnerability in Juniper Networks PTX Series routers running Junos OS Evolved. The On-Box Anomaly Detection Framework exposes a Python REST API on port 8160/TCP bound to all interfaces without authentication, allowing any network-based attacker to execute arbitrary commands as root via crafted API requests. CVSS 9.8 with no user interaction required.
CVE-2026-21902 is a critical pre-authentication remote code execution vulnerability affecting Juniper Networks PTX Series routers running Junos OS Evolved version 25.4R1-EVO. The flaw resides in the On-Box Anomaly Detection Framework, an internal security monitoring service that was inadvertently exposed to external network access due to incorrect default permissions (CWE-276/CWE-732).
The vulnerability stems from a Python-based REST API server (api_server.py) that binds to 0.0.0.0:8160/TCP instead of the localhost interface. This service is part of the On-Box Anomaly Detection Framework and was designed to be reachable only by other internal processes over the internal routing instance. However, the incorrect permission assignment causes the service to listen on all network interfaces, making it accessible to any unauthenticated remote attacker.
The exploitation chain leverages four REST API endpoints that require no authentication:
1. POST /config/command/<name> — Creates a Command definition with type RE-SHELL containing arbitrary shell syntax 2. POST /config/dag/<name> — Defines a DAG (Directed Acyclic Graph) workflow referencing the malicious command 3. POST /config/dag-instance/<name> — Creates a scheduled execution instance with immediate timing 4. POST /config/commit — Validates and persists the configuration, triggering execution
When the schedule_enforcer.py process (running as root) detects the scheduled DAG instance, it retrieves the command definition and passes the attacker-controlled syntax field directly to subprocess.run(command, shell=True), achieving arbitrary command execution with root privileges. The vulnerable code path flows through execute_dag_instance() -> execute_dag() -> run_bfs_on_dag_actions() -> execute_command(), with no input sanitization at any stage.
The service is enabled by default on affected versions without requiring any specific configuration, meaning all PTX Series routers running vulnerable Junos OS Evolved versions are exposed out of the box. Successful exploitation grants complete device control including configuration manipulation (routing tables, BGP sessions, ACLs), traffic interception or redirection, credential and cryptographic key exfiltration, and service disruption via control-plane interference.
Juniper Networks released this as an out-of-cycle emergency security bulletin (JSA107128) on February 25, 2026, indicating the severity and urgency. The watchTowr Labs team published a detailed technical analysis and proof-of-concept on March 3, 2026, demonstrating the full exploitation chain. Multiple government agencies including the Cyber Security Agency of Singapore issued alerts. No confirmed active exploitation in the wild has been reported, though the trivial exploitation complexity and public PoC availability make exploitation highly likely.
MITRE ATT&CK techniques used in TL-2026-0269
credential-access
discovery
T1046 Network Service Discovery; T1082 System Information Discovery
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter
privilege-escalation
T1068 Exploitation for Privilege Escalation
defense-evasion
command-and-control
T1071 Application Layer Protocol
initial-access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
impact
T1489 Service Stop; T1498 Network Denial of Service; T1565 Data Manipulation
Impact
Persistence
T1505 Server Software Component
persistence
T1543 Create or Modify System Process
Reconnaissance
T1595.001 Active Scanning: Scanning IP Blocks; T1595.002 Active Scanning: Vulnerability Scanning
defense-impairment
Affected products and versions in CVE-2026-21902
- Juniper Networks — Junos OS Evolved
Vulnerable versions: 25.4R1-EVO (all builds before 25.4R1-S1-EVO)
Fixed in: 25.4R1-S1-EVO; 25.4R2-EVO; 26.2R1-EVO - Juniper Networks — PTX Series Routers
Vulnerable versions: All PTX models running vulnerable Junos OS Evolved versions
Fixed in: PTX models running patched Junos OS Evolved
Remediation for CVE-2026-21902
Patches
- Junos OS Evolved 25.4R1-S1-EVO (emergency out-of-cycle patch)
- Junos OS Evolved 25.4R2-EVO
- Junos OS Evolved 26.2R1-EVO
Immediate actions
- Block TCP port 8160 at network perimeter via ACLs and firewall filters
- Restrict management plane access to trusted internal subnets only
- Disable the vulnerable service using CLI command: request pfe anomalies disable
- Audit PTX Series router fleet for Junos OS Evolved version 25.4R1-EVO exposure
- Monitor for unauthorized connections to port 8160/TCP on all PTX Series devices
Workarounds
- Disable On-Box Anomaly Detection: request pfe anomalies disable
- Apply firewall filter to block external access to TCP port 8160
- Restrict management interface access via lo0 filter to trusted hosts only
Longer-term hardening
- Deploy network segmentation isolating router management interfaces from untrusted networks
- Implement out-of-band management networks for all critical network infrastructure
- Deploy network-based IDS/IPS signatures for anomalous HTTP traffic to port 8160
- Establish automated version compliance monitoring for Juniper infrastructure
- Review and harden all Juniper device management plane access controls
CVEs associated with CVE-2026-21902
Weaknesses (CWE) in CVE-2026-21902
Timeline of CVE-2026-21902
- CVE-2026-21902 published to NVD; Juniper Networks releases out-of-cycle emergency security bulletin JSA107128
- Threat intelligence reports begin covering the vulnerability; ThreatIntelReport publishes initial technical analysis
- Juniper confirms patched versions 25.4R1-S1-EVO and 25.4R2-EVO available; workaround via request pfe anomalies disable documented
- Cyber Security Agency of Singapore issues Alert AL-2026-020; multiple security news outlets publish analyses and risk assessments
- UpGuard and additional security vendors publish risk assessments and exposure analyses for enterprise customers
- Vendor and third-party trackers (runZero) clarify the precise vulnerable version boundary: 25.4R1-EVO through versions prior to 25.4R1-S1-EVO, and 25.4R1-S1-EVO through versions prior to 25.4R2-EVO; releases before 25.4R1-EVO confirmed not vulnerable.
- watchTowr Labs researcher McCaulay Hudson (@_mccaulay) credited as discoverer and author of the technical write-up and public PoC exploit.
- NVD record last modified with additional details including CVSS 4.0 score of 9.3 and updated CWE/CAPEC references
- watchTowr Labs publishes detailed technical analysis with full exploitation chain walkthrough and PoC tools on GitHub
- Purple Ops publishes detailed exploitation guide with step-by-step API request examples and detection recommendations
- Cyble Research and Intelligence Labs includes CVE-2026-21902 in weekly vulnerability report, confirming ongoing risk assessment
- As of 2026-05-29, CVE-2026-21902 remains PATCHED: Juniper's out-of-cycle fixes (25.4R1-S1-EVO/25.4R2-EVO) are public, the flaw was vendor-discovered with no confirmed in-the-wild exploitation, and it is not in CISA KEV. A public watchTowr PoC keeps residual risk for unpatched PTX fleets, but no active campaign or actor is reported.
Update history for TL-2026-0269
- 2026-07-19 — CVE-2026-21902: Unauthenticated RCE in Juniper Junos OS Evolved via Exposed On-Box Anomaly Detection Framework REST API: What changed No severity/exploitability/status escalation — the newer report's own text confirms no in-the-wild exploitation and no CISA KEV listing, matching the existing PATCHED/no-confirmed-exploitation record. New indicators (8) 5 addit
Sources cited for CVE-2026-21902
- Juniper Out-of-Cycle Security Bulletin JSA107128
- NVD - CVE-2026-21902
- watchTowr Labs: Junos OS Evolved CVE-2026-21902 Pre-Auth RCE Analysis
- watchTowr Labs PoC - CVE-2026-21902
- Purple Ops CVE-2026-21902 Technical Analysis
- CVE-2026-21902: Juniper PTX Routers One Packet to Root
- Critical Juniper PTX Junos OS Evolved Flaw Enables Unauthenticated Root Takeover
- Cyber Security Agency of Singapore Alert AL-2026-020
- Critical Flaw in Juniper PTX Routers: Unauthenticated Root Access Discovered
- Juniper Issues Emergency Patch for Critical PTX Router RCE
- runZero: Juniper Junos OS Evolved CVE-2026-21902 Detection
- Cyble Weekly Vulnerabilities Report - March 19, 2026
- UpGuard: Critical Juniper Networks RCE CVE-2026-21902
- Rescana: Critical CVE-2026-21902 Vulnerability Analysis
Detection coverage for TL-2026-0269
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0269 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.