CVE-2026-33778
7.5Juniper Networks · Junos OS
A malformed ISAKMP packet allows an unauthenticated, network-based attacker to trigger a crash in the kmd or iked processes on Juniper Junos OS, resulting in a complete Denial-of-Service for VPNs.
Executive summary
An unauthenticated remote Denial-of-Service vulnerability in Juniper Networks Junos OS allows attackers to disrupt VPN services by sending a specifically malformed ISAKMP packet.
Vulnerability
This vulnerability involves improper validation of input within the IPsec library used by the kmd and iked processes. An unauthenticated attacker can crash these processes remotely, preventing the establishment of new security associations and causing a complete service outage.
Business impact
Successful exploitation poses a significant risk to business continuity by disabling VPN connectivity for remote workers and branch offices. While the CVSS score of 7.5 reflects a high severity, the impact is primarily availability-based, meaning organizations may suffer from total loss of secure network access until the affected processes are recovered.
Remediation
Immediate Action: Upgrade to the patched releases provided by Juniper Networks, specifically 22.4R3-S9, 23.2R2-S6, 23.4R2-S7, 24.2R2-S4, 24.4R2-S3, 25.2R1-S2, or 25.4R1 and subsequent versions.
Proactive Monitoring: Monitor system logs for repeated process restarts of kmd or iked, which may indicate active exploitation attempts targeting the IPsec stack.
Compensating Controls: Implement access control lists at the network perimeter to restrict ISAKMP traffic to known and trusted IP addresses, effectively limiting the attack surface for unauthorized actors.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for complete service disruption, organizations should prioritize the deployment of the vendor-supplied patches across all affected SRX and MX series hardware. Administrators should test the updates in a staging environment if possible, but the absence of authentication requirements makes this a high-priority update for all perimeter-facing infrastructure.