CyberMax
Home › Exploited CVEs

Juniper known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 8 Juniper CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2025-10-02), and 0 are known to be used in ransomware campaigns.

Juniper CVEs added to CISA KEV per year
2022: 1202212023: 5202352025: 220252

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Juniper products

Junos OS (7), ScreenOS (1).

All Juniper CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2015-7755ScreenOSScreenOS Improper Authentication2025-10-022025-10-2361.1%–
CVE-2025-21590Junos OSJunos OS Improper Isolation or Compartmentalization2025-03-132025-04-031.7%–
CVE-2023-36851Junos OSJunos OS SRX Series Missing Authentication for Critical Function2023-11-132023-11-171.1%–
CVE-2023-36847Junos OSJunos OS EX Series Missing Authentication for Critical Function2023-11-132023-11-1783.5%–
CVE-2023-36846Junos OSJunos OS SRX Series Missing Authentication for Critical Function2023-11-132023-11-1793.5%–
CVE-2023-36845Junos OSJunos OS EX Series and SRX Series PHP External Variable Modification2023-11-132023-11-1795.1%–
CVE-2023-36844Junos OSJunos OS EX Series PHP External Variable Modification2023-11-132023-11-1790.0%–
CVE-2020-1631Junos OSJunos OS Path Traversal2022-03-252022-04-154.8%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors