PT-2026-56926 · Juniper Networks · Junos Evolved

CVE-2026-33794

·

Published

2026-07-09

·

Updated

2026-07-13

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS Evolved on PTX versions 24.4R2-EVO through 24.4R2-S2-EVO Junos OS Evolved on PTX versions 25.2 through 25.2R1-EVO
Description An improper check for unusual or exceptional conditions in the advanced forwarding toolkit (evo-aftmand) allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). By generating continuous routing updates that result in unilist ECMP routes, an attacker can trigger internal state corruption, causing the evo-aftmand process on the PFE to crash. Unified list (unilist) ECMP routes are a behavior where multiple equal-cost routes share a single logical next-hop list entry, allowing the router to load balance traffic across that list. Recovery requires manual intervention via a system reboot or restarting the FPC.
Recommendations Update Junos OS Evolved on PTX versions 24.4R2-EVO through 24.4R2-S2-EVO to version 24.4R2-S3-EVO. Update Junos OS Evolved on PTX versions 25.2 through 25.2R1-EVO to version 25.2R2-EVO.

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33794

Affected Products

Junos Evolved