OVERVIEW CVE-2026-33778 is an input validation vulnerability in the IPsec library used by Juniper Networks Junos OS on SRX and MX Series devices. The flaw allows unauthenticated, network-based attackers to trigger a Denial-of-Service condition by sending a malformed ISAKMP packet that crashes the kmd/iked process. Repeated exploitation prevents establishment of new VPN connections on affected devices. SEVERITY This vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector, low complexity, and no authentication required. While confidentiality and integrity are not impacted, the availability impact is high. The vulnerability affects multiple versions of Junos OS across both SRX and MX Series platforms, with patches available in versions 22.4R3-S9 and later across various release branches. EXPLOITATION STATUS The vulnerability is not currently being actively exploited in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and inactive status on threat tracking lists. The EPSS score of 0.00136 reflects minimal real-world exploitation likelihood at this time. However, the straightforward nature of the attack (sending a malformed packet) suggests organizations should prioritize patching to prevent future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 22.4R3-S9CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.2, < 23.2R2-S6CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.4, < 23.4R2-S7CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.2, < 24.2R2-S4CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.4, < 24.4R2-S3CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.