Junglewise Threat Intelligence

CVE-2026-33794: Juniper Junos OS Evolved DoS in advanced forwarding toolkit

CVE-2026-33794 · Severity: medium · CVSS 5.9 · Published 2026-07-09

Technologies: Juniper Networks Junos OS Evolved. Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks' Junos OS Evolved on PTX Series routers can cause the device's forwarding toolkit to crash, leading to a total loss of service. This occurs when the router processes specific types of complex routing updates, resulting in internal state corruption. An exploit would require manual intervention, such as a system reboot or hardware restart, to restore network operations.

Technical details

An Improper Check for Unusual or Exceptional Conditions (CWE-754) exists in the evo-aftmand process of Junos OS Evolved on PTX Series devices. The vulnerability is triggered when processing continuous routing updates that result in unified list (unilist) Equal-Cost Multi-Path (ECMP) routes. This leads to internal state corruption and a crash of the evo-aftmand process on the Packet Forwarding Engine (PFE). While the attack vector is network-based and unauthenticated, successful exploitation depends on a sequence of events outside the attacker's direct control, resulting in a High complexity (AC:H) rating. Recovery requires a manual reboot of the system or a restart of the Flexible PIC Concentrator (FPC).

Affected products

  • Juniper Networks Junos OS Evolved 24.4R2-EVO before 24.4R2-S3-EVO, 25.2 before 25.2R2-EVO

Timeline

  • 2026-07-09: advisory: Initial publication of JSA110073

References

Related threats