Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-21901
Juniper Networks Junos OS — Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
L L N H N N N H 6.7 .0016 5.2 —
AFFECTED
Product Versions Fixed
Junos OS 22.3 – —
Junos OS Evolved 23.2 – —
TIMELINE
Jan 5 Reserved by juniper
Jul 9 Published (CNA: juniper)
Aug 26 EXPLOIT PUBLISHED — CVE-2026-21901 (Juniper Networks Junos OS). Public exploit reference added.
Description
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).
A local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition.
This issue affects:
Junos OS:
* from 22.3 before 22.3R3-S5;
* from 22.4 before 22.4R3-S10;
* from 23.2 before 23.2R2-S7;
* from 23.4 before 23.4R2-S8.
This issue does not affect Junos OS before 22.3R1.
Junos OS Evolved:
* from 22.3R1-EVO before 23.2R2-S7-EVO;
* from 23.4 before 23.4R2-S8-EVO.
This issue does not affect Junos OS Evolved before 22.3R1-EVO.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 5, 2026 | Reserved | Reserved by juniper |
| July 9, 2026 | Published | Published (CNA: juniper) |
| August 26, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-21901 (Juniper Networks Junos OS). Public exploit reference added. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Juniper Networks | Junos OS | — | 22.3 | — |
| Juniper Networks | Junos OS Evolved | — | 23.2 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-21901 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.