generated: '2026-09-18' method: searched source: https://www.juniper.net/us/en/report-a-security-vulnerability.html provider: Juniper Networks providerId: juniper summary: >- Juniper runs a real, long-standing coordinated disclosure program through the Juniper Networks Security Incident Response Team (SIRT), with a named mailbox, a published PGP key, a fixed quarterly advisory calendar and a public advisory archive. It does NOT publish a /.well-known/security.txt on any host — the program is discoverable only by finding the page. program: name: Juniper Networks Security Incident Response Team (SIRT) policy_url: https://www.juniper.net/us/en/report-a-security-vulnerability.html policy_status: 200 contact_email: sirt@juniper.net pgp_key: >- Published on the reporting page as a downloadable plain-text public key. advance_notification: >- Explicitly none. The policy states Juniper "does not provide an advance notification service" and that "security fixes and advisories are freely available from our web site." commitment: >- "All issues reported to the Security Incident Response Team will be investigated. Fixes will be generated where necessary and when applicable, per our policies, a security advisory will be released." sla: null sla_note: No response or remediation timeline is stated. disclosure_schedule: cadence: quarterly dates: second Wednesday of January, April, July and October scope: all Juniper products out_of_cycle: >- Reserved for active exploitation of a zero-day or multi-vendor issues. source: https://supportportal.juniper.net/s/article/Overview-of-the-Juniper-Networks-SIRT-Quarterly-Security-Bulletin-Publication-Process advisories: url: https://advisory.juniper.net/ status: 200 note: >- A 239-byte meta-refresh shim that forwards to the KB security-advisories channel, which now lands on supportportal.juniper.net. The short URL works but is a redirect stub, not the archive itself. bug_bounty: platform: hackerone url: https://hackerone.com/junipernetworks status: 200 pays_bounties: unknown note: >- A HackerOne program page exists and loads, but the program JSON is no longer served anonymously, so whether it pays bounties or is disclosure-only could not be verified. Recorded as found, not as a bounty. web_property_carve_out: note: >- Post-acquisition split: vulnerabilities in Juniper PRODUCTS go to sirt@juniper.net, while vulnerabilities in the WEBSITE are directed to security@hpe.com. security_txt: published: false probed: - url: https://www.juniper.net/.well-known/security.txt status: 404 - url: https://api.mist.com/.well-known/security.txt status: 404 - url: https://support.juniper.net/.well-known/security.txt status: 200 note: soft-404 HTML shell, not a document gap: >- The single cheapest fix available to Juniper here — the program, the contact, the policy URL and the PGP key all already exist and would populate an RFC 9116 file verbatim. maintainers: - FN: Kin Lane email: kin@apievangelist.com