CVE-2026-33794
published 2026-07-09CVE-2026-33794: An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on…
PriorityP336medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.40%
32.8th percentile
An Improper Check for Unusual or Exceptional Conditions vulnerability in the
advanced forwarding toolkit (evo-aftmand)
of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the
evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control.
Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC.
This issue affects Junos OS Evolved on PTX :
* from 24.4R2-EVO before 24.4R2-S3-EVO;
* from 25.2 before 25.2R2-EVO.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos_os_evolved | — | — |
| juniper | junos_os_evolved | — | — |
| juniper | junos_os_evolved | — | — |
| juniper | junos_os_evolved | — | — |
| juniper | junos_os_evolved | — | — |
| juniper | junos_os_evolved | — | — |
| juniper | junos_os_evolved | — | — |
| juniper_networks | junos_os_evolved | >= 24.4R2-EVO < 24.4R2-S3-EVO | 24.4R2-S3-EVO |
| juniper_networks | junos_os_evolved | >= 25.2 < 25.2R2, 25.2R2-EVO | 25.2R2, 25.2R2-EVO |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Green
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Juniper Junos OS Evolved prior 24.4R2-S3-EVO/25.2R2/25.2R2-EVO evo-aftmand state issue
vuldb·2026-07-09·CVSS 5.9
CVE-2026-33794 [MEDIUM] Juniper Junos OS Evolved prior 24.4R2-S3-EVO/25.2R2/25.2R2-EVO evo-aftmand state issue
A vulnerability was found in Juniper Junos OS Evolved. It has been declared as critical. The affected element is an unknown function of the component evo-aftmand. Such manipulation leads to state issue.
This vulnerability is documented as CVE-2026-33794. The attack can be executed remotely. There is not any exploit available.
GHSA
An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated
ghsa_unreviewed·2026-07-09
CVE-2026-33794 [HIGH] CWE-754 An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated
An Improper Check for Unusual or Exceptional Conditions vulnerability in the
advanced forwarding toolkit (evo-aftmand)
of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the
evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control.
Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-09
Published