CVE-2026-21906
7.5Juniper Networks · Junos OS
An improper handling of exceptional conditions in the Junos OS packet forwarding engine allows unauthenticated attackers to cause a device crash and traffic loss via specific ICMP packets.
Executive summary
A critical vulnerability in Juniper Networks Junos OS on SRX Series devices allows unauthenticated remote attackers to trigger a system crash and denial of service.
Vulnerability
The flaw exists in the packet forwarding engine (PFE) when PowerMode IPsec (PMI) and GRE performance acceleration are enabled. An unauthenticated network-based attacker can send a specific ICMP packet through a GRE tunnel, triggering an exception that forces the PFE to crash and restart, resulting in immediate traffic loss.
Business impact
Successful exploitation of this vulnerability results in a denial of service for the affected SRX Series gateway. Given that the PFE handles all transit traffic, a crash will interrupt all network communications passing through the device, leading to significant operational downtime. With a CVSS score of 7.5, this high-severity issue poses a substantial risk to network availability and business continuity for organizations relying on these devices for secure connectivity.
Remediation
Immediate Action: Upgrade Junos OS to the patched release versions: 21.4R3-S12, 22.4R3-S8, 23.2R2-S5, 23.4R2-S5, 24.2R2-S3, 24.4R2-S1, 25.2R1-S1, 25.2R2, or any subsequent release.
Proactive Monitoring: Monitor device logs for unexpected PFE crashes or restart events and utilize the command "show security flow pmi statistics" to audit the status of PowerMode IPsec configurations.
Compensating Controls: If patching is not immediately feasible, consider disabling PowerMode IPsec (PMI) or GRE performance acceleration if they are not strictly required for your specific operational environment.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant risk to the stability of Juniper SRX security gateways. Because the attack vector is unauthenticated and targets the core packet forwarding functionality, organizations must prioritize patching these systems during the next maintenance window. Apply the provided vendor updates immediately to ensure the PFE remains resilient against this denial of service attack.