CVE-2026-57029: Juniper Junos OS Evolved
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
Affected products
- Juniper Junos OS Evolved: version 23.2 only; version 23.4 only; version 24.2 only; version 24.4 only; version 25.2 only
Published 2026-07-09. Last modified 2026-07-13.