CVE-2026-21907
Severity CVSS v4.0:
HIGH
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
15/01/2026
Last modified:
23/01/2026
Description
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space allows the use of static key ciphers (ssl-static-key-ciphers), reducing the confidentiality of on-path traffic communicated across the connection. These ciphers also do not support Perfect Forward Secrecy (PFS), affecting the long-term confidentiality of encrypted communications.This issue affects all versions of Junos Space before 24.1R5.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:juniper:junos_space:*:*:*:*:*:*:*:* | 24.1 (excluding) | |
| cpe:2.3:a:juniper:junos_space:24.1:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:juniper:junos_space:24.1:r2:*:*:*:*:*:* | ||
| cpe:2.3:a:juniper:junos_space:24.1:r3:*:*:*:*:*:* | ||
| cpe:2.3:a:juniper:junos_space:24.1:r4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



