8.3
CVE-2026-33779 - Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially modify it. When an SRX device is provisioned to connect to…
8.7
CVE-2026-5982 - D-Link DIR-605L POST Request formAdvNetwork buffer overflow
A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the argument curTime results in buffer overflow. Remote exploitation of the attack is p…
7.1
CVE-2026-33775 - Junos OS: MX Series: Mismatch between configured and received packet types causes memory leak in bb…
A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If the authentication packet-type option is co…
5.3
CVE-2026-40151 - PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents …
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application has no authenticati…
8.7
CVE-2026-33782 - Junos OS: MX Series: In specific DHCPv6 scenarios jdhcpd memory increases continuously with subscri…
A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS). In a DHCPv6 over PPPoE, or D…
7.1
CVE-2026-33780 - Junos OS and Junos OS Evolved: In an EVPN-MPLS scenario churn of ESI routes causes a memory leak in…
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS). In an EVPN-MPLS…
6.9
CVE-2026-33773 - Junos OS: EX Series, QFX Series: If the same egress filter is configured on both an IRB and a physi…
An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks. When the same family inet or i…
6.8
CVE-2026-33786 - Junos OS: SRX1600, SRX2300, SRX4300: When a specific show command is executed chassisd crashes
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI co…
7
CVE-2026-21916 - Junos OS: A low privileged user can escalate their privileges so that they can login as root
A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system. When after a user has performed a specific 'file li…
7.4
CVE-2026-40153 - PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypas…
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using shell=False (line 88) for security. This…