SB2026050814 - MitM attack in Junos OS



SB2026050814 - MitM attack in Junos OS

Published: May 8, 2026

Security Bulletin ID SB2026050814
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Following of a Certificate's Chain of Trust (CVE-ID: CVE-2026-33779)

The vulnerability allows a remote attacker to disclose sensitive information and potentially modify it.

The vulnerability exists due to improper following of a certificate's chain of trust in J-Web when an SRX device is provisioned to connect to Security Director cloud. A remote attacker can intercept device-to-cloud communication using a machine-in-the-middle position to disclose sensitive information and potentially modify it.

The issue affects communication between SRX devices and Security Director cloud, and exposed data may include credentials.


Remediation

Install update from vendor's website.