Juniper Networks security patch release for CVE-2026-21902
Security Patch Release
Summary
Hide ▲
Show ▼
Juniper Networks has released fixes for CVE-2026-21902 in Junos OS Evolved on PTX Series routers, closing a flaw that could let an unauthenticated attacker run code as root. The vendor says fixed versions are 25.4R1-S1-EVO, 25.4R2-EVO, and 26.2R1-EVO. Administrators that cannot patch immediately should restrict access with firewall filters or ACLs, or disable the vulnerable service.
Related Happenings
Linux distros patch release for Fragnasia (CVE-2026-46300)
Security Patch Release
First: 14.05.2026 10:34
Last: 14.05.2026 10:34
Sources 1
About this happening:
Linux distros are rolling out **patches** for **CVE-2026-46300**, a high-severity kernel flaw that can let unprivileged local attackers gain **root** on vulnerable Linux systems....
Linux distros patch release for Fragnasia (CVE-2026-46300)
Security Patch ReleaseAbout this happening: Linux distros are rolling out **patches** for **CVE-2026-46300**, a high-severity kernel flaw that can let unprivileged local attackers gain **root** on vulnerable Linux systems....
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
**Major Linux distributions** are rolling out fixes for **Dirty Frag**, the **Linux kernel** patch release that covers **CVE-2026-43284** and **CVE-2026-43500**. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: **Major Linux distributions** are rolling out fixes for **Dirty Frag**, the **Linux kernel** patch release that covers **CVE-2026-43284** and **CVE-2026-43500**. The update matter...
Cisco security patch release for CVE-2026-20188
Security Patch Release
First: 06.05.2026 21:06
Last: 06.05.2026 21:06
Sources 1
About this happening:
**Cisco** released security updates for **CVE-2026-20188**, a high-severity **DoS vulnerability** in **Crosswork Network Controller (CNC)** and **Network Services Orchestrator (NS...
Cisco security patch release for CVE-2026-20188
Security Patch ReleaseAbout this happening: **Cisco** released security updates for **CVE-2026-20188**, a high-severity **DoS vulnerability** in **Crosswork Network Controller (CNC)** and **Network Services Orchestrator (NS...
PAN-OS User-ID Authentication Portal mitigation guidance (CVE-2026-0300)
Advisory/Mitigation
First: 06.05.2026 09:14
Last: 06.05.2026 09:14
Sources 1
About this happening:
Palo Alto Networks issued **mitigation guidance** for **CVE-2026-0300** after the **PAN-OS User-ID Authentication Portal** flaw was reported **exploited in the wild**, leaving pub...
PAN-OS User-ID Authentication Portal mitigation guidance (CVE-2026-0300)
Advisory/MitigationAbout this happening: Palo Alto Networks issued **mitigation guidance** for **CVE-2026-0300** after the **PAN-OS User-ID Authentication Portal** flaw was reported **exploited in the wild**, leaving pub...
Progress Software security patch release for CVE-2026-4670
Security Patch Release
First: 04.05.2026 19:34
Last: 04.05.2026 19:34
Sources 1
About this happening:
**Progress Software** has released **MOVEit Automation** updates to fix **CVE-2026-4670** and **CVE-2026-5174**, including a **critical authentication bypass** that could expose e...
Progress Software security patch release for CVE-2026-4670
Security Patch ReleaseAbout this happening: **Progress Software** has released **MOVEit Automation** updates to fix **CVE-2026-4670** and **CVE-2026-5174**, including a **critical authentication bypass** that could expose e...
Timeline
-
26.02.2026 18:42 2 articles · 3mo ago
Juniper Networks publishes fixes for CVE-2026-21902
Mitigation Patch UpdateJuniper Networks published fixes for CVE-2026-21902 affecting Junos OS Evolved on PTX Series routers, a flaw in the On-Box Anomaly Detection framework that could let an unauthenticated attacker reach an externally exposed port, execute code as root, and take full control of an affected device. Fixed releases are 25.4R1-S1-EVO, 25.4R2-EVO, and 26.2R1-EVO, and administrators unable to patch immediately were advised to restrict access with firewall filters or Access Control Lists (ACLs) or disable the vulnerable service with `request pfe anomalies disable`.
Show sources
- Critical Juniper Networks PTX flaw allows full router takeover — www.bleepingcomputer.com — 26.02.2026 18:42
- Critical Juniper Networks PTX flaw allows full router takeover — www.bleepingcomputer.com — 26.02.2026 18:42