VulnSea

Arista Networks has 45 CVEs on record. Disclosure cadence is accelerating: 45 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 45. The median CVSS is 6.5 (medium), with 5 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-532 (5) and CWE-20 (3). Most affected products: EOS (41), VeloCloud Edge (3), VeloCloud (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
45 prev 0

Products

  • EOS 41
  • VeloCloud Edge 3
  • VeloCloud 1
45
Total CVEs
5
Critical
0
CISA KEV
0
Exploited

Arista Networks vulnerabilities

CVEs affecting Arista Networks, newest first. Open any entry for full detail, references, and exploit status.

45 CVEsRSS

CVE-2026-73462Medium· 6.5
5d ago

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

SunlitArista Networks · EOSEPSS 0.24%via NVD
CVE-2026-73443Medium· 4.7
5d ago

On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement …

On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement …

SunlitArista Networks · EOSEPSS 0.27%via NVD
CVE-2026-73442Low· 3.0
5d ago

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a s…

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a s…

SunlitArista Networks · EOSEPSS 0.21%via NVD
CVE-2026-73456Critical· 10.0
5d ago

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting a…

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting a…

MidnightArista Networks · EOSEPSS 0.75%via NVD
CVE-2026-73457Medium· 5.3
5d ago

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authentica…

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authentica…

SunlitArista Networks · EOSEPSS 0.32%via NVD
CVE-2026-86106Critical· 9.6
5d ago

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

MidnightArista Networks · VeloCloud EdgeEPSS 0.38%via NVD
CVE-2026-86107Medium· 5.9
5d ago

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful …

SunlitArista Networks · VeloCloudEPSS 0.35%via NVD
CVE-2026-77190Medium· 6.5
5d ago

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent …

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent …

SunlitArista Networks · EOSEPSS 0.28%via NVD
CVE-2026-73469Medium· 5.8
5d ago

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on…

SunlitArista Networks · EOSEPSS 0.29%via NVD
CVE-2026-73468Medium· 6.5
5d ago

A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.

A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.

SunlitArista Networks · EOSEPSS 0.25%via NVD
CVE-2026-73440Medium· 4.2
5d ago

On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized…

On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized…

SunlitArista Networks · EOSEPSS 0.26%via NVD
CVE-2026-19640Medium· 4.2
5d ago

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissi…

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissi…

SunlitArista Networks · EOSEPSS 0.19%via NVD
CVE-2026-73435High· 8.2
5d ago

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured…

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured…

TwilightArista Networks · EOSEPSS 0.16%via NVD
CVE-2026-73453Critical· 10.0
5d ago

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime …

MidnightArista Networks · EOSEPSS 0.75%via NVD
CVE-2026-73436Medium· 6.5
5d ago

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

SunlitArista Networks · EOSEPSS 0.23%via NVD
CVE-2026-73455High· 7.5
5d ago

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.

TwilightArista Networks · EOSEPSS 0.48%via NVD
CVE-2026-73438Medium· 5.3
5d ago

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 ag…

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 ag…

SunlitArista Networks · EOSEPSS 0.21%via NVD
CVE-2026-73463Medium· 5.3
5d ago

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whos…

SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-73445Medium· 4.9
5d ago

On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active

On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active. This does not affect B…

SunlitArista Networks · EOSEPSS 0.33%via NVD
CVE-2026-73439High· 7.5
5d ago

On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the …

On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the …

TwilightArista Networks · EOSEPSS 0.33%via NVD
CVE-2026-73461High· 8.0
5d ago

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. Th…

TwilightArista Networks · EOSEPSS 0.30%via NVD
CVE-2026-73454High· 8.1
5d ago

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the accoun…

TwilightArista Networks · EOSEPSS 0.30%via NVD
CVE-2026-73464High· 8.8
5d ago

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbi…

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbi…

TwilightArista Networks · EOSEPSS 0.48%via NVD
CVE-2026-2380High· 7.4
5d ago

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded o…

TwilightArista Networks · EOSEPSS 0.25%via NVD
CVE-2026-73447Critical· 9.1
5d ago

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista E…

MidnightArista Networks · EOSEPSS 0.76%via NVD
CVE-2026-86109Medium· 6.6
5d ago

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either suffic…

SunlitArista Networks · VeloCloud EdgeEPSS 0.24%via NVD
CVE-2026-86108High· 8.0
5d ago

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Success…

TwilightArista Networks · VeloCloud EdgeEPSS 0.83%via NVD
CVE-2026-73450Medium· 6.9
5d ago

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-73446High· 7.4
5d ago

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacen…

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacen…

TwilightArista Networks · EOSEPSS 0.25%via NVD
CVE-2026-73459High· 7.4
5d ago

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This …

TwilightArista Networks · EOSEPSS 0.16%via NVD
Arista Networks vulnerabilities (CVEs) · VulnSea