OVERVIEW CVE-2026-21919 is an Incorrect Synchronization vulnerability affecting Juniper Networks Junos OS and Junos OS Evolved management daemons (mgd). The vulnerability arises when NETCONF sessions are rapidly established and disconnected, causing a locking issue that leaves mgd processes in an unusable state. When sufficient mgd processes are exhausted, the device becomes unmanageable and requires a power cycle for recovery. The vulnerability impacts Junos OS versions 23.4 through 24.4 and corresponding Junos OS Evolved versions, though earlier releases before 23.4R1 are unaffected. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) with a network-based attack vector, low attack complexity, and low privilege requirements. The attack requires no user interaction and results in high availability impact through complete denial of service of the management plane. While the confidentiality and integrity of data remain unaffected, the operational impact is severe as administrators lose the ability to manage affected devices. The EPSS score of 0.00045 indicates this vulnerability is not yet widely exploited in the wild. EXPLOITATION STATUS There is no evidence of active exploitation, and this vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog. The Faucet Risk Score of 35.0/100 reflects low immediate threat, and the vulnerability remains inactive on community hotlists. No public exploit code availability has been documented, though the attack method is relatively straightforward for authenticated attackers with low privileges.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.4:r1-s2:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.4:r2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.