Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2020-1631Juniper Junos OS Path Traversal Vulnerability
9.8 critical · over the network, without login · CISA deadline was 15 Apr 22
- CVE-2023-36845Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability
9.8 critical · over the network, without login · CISA deadline was 17 Nov 23
- CVE-2023-36851Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
5.3 medium · over the network, without login · CISA deadline was 17 Nov 23
- CVE-2023-36847Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
5.3 medium · over the network, without login · CISA deadline was 17 Nov 23
- CVE-2023-36846Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
5.3 medium · over the network, without login · CISA deadline was 17 Nov 23
- CVE-2023-36844Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
5.3 medium · over the network, without login · CISA deadline was 17 Nov 23
- CVE-2025-21590Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
4.4 medium · locally only, with admin rights only · CISA deadline was 3 Apr 25
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- SSH Protokoll: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
WID-SEC-W-2023-3174 · 9 Oct
- jQuery: Schwachstelle ermöglicht Cross-Site Scripting
WID-SEC-W-2023-0558 · 5 Oct
- Linux Kernel: Mehrere Schwachstellen
WID-SEC-W-2026-1232 · 5 Oct
- python-cryptography: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
WID-SEC-W-2023-0557 · 17 Sept
- OpenSSH: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2024-1486 · 16 Sept
- Red Hat Enterprise Linux: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
WID-SEC-W-2026-3129 · 1 Sept
- Samba: Mehrere Schwachstellen ermöglichen Denial of Service
WID-SEC-W-2026-3128 · 1 Sept
- OpenSSL: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2022-0585 · 21 Aug
Version history & changelog · as detected by patchletter
No releases recorded yet — the source was just added.
An email as soon as a new Junos OS version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Junos OS version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/junos)https://patchletter.com/badge/junos.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).