VulnSea

Arista Networks has 45 CVEs on record. Disclosure cadence is accelerating: 45 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 45. The median CVSS is 6.5 (medium), with 5 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-532 (5) and CWE-20 (3). Most affected products: EOS (41), VeloCloud Edge (3), VeloCloud (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
45 prev 0

Products

  • EOS 41
  • VeloCloud Edge 3
  • VeloCloud 1
45
Total CVEs
5
Critical
0
CISA KEV
0
Exploited

Arista Networks vulnerabilities

CVEs affecting Arista Networks, newest first. Open any entry for full detail, references, and exploit status.

45 CVEsRSS

CVE-2026-73460Medium· 6.1
1w ago

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may r…

▾ SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-73437Critical· 9.6
1w ago

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured a…

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured a…

▾ MidnightArista Networks · EOSEPSS 0.21%via NVD
CVE-2026-73444Medium· 4.7
1w ago

On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentica…

On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentica…

▾ SunlitArista Networks · EOSEPSS 0.30%via NVD
CVE-2026-19655Medium· 6.5
1w ago

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…

▾ SunlitArista Networks · EOSEPSS 0.19%via NVD
CVE-2026-73458High· 8.2
1w ago

On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down

On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes …

▾ TwilightArista Networks · EOSEPSS 0.40%via NVD
CVE-2026-73467Medium· 6.3
1w ago

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

▾ SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-73466Medium· 6.3
1w ago

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit th…

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit th…

▾ SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-73465Medium· 6.3
1w ago

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exp…

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exp…

▾ SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-73451Medium· 4.8
1w ago

On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of second…

On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of second…

▾ SunlitArista Networks · EOSEPSS 0.23%via NVD
CVE-2026-19641Medium· 5.3
1w ago

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources,…

▾ SunlitArista Networks · EOSEPSS 0.34%via NVD
CVE-2026-77191Low· 2.6
1w ago

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the …

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the …

▾ SunlitArista Networks · EOSEPSS 0.22%via NVD
CVE-2026-75943Low· 2.6
1w ago

A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout

A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass w…

▾ SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-75944Low· 2.6
1w ago

A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system

A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access contro…

▾ SunlitArista Networks · EOSEPSS 0.22%via NVD
CVE-2026-75945Low· 2.6
1w ago

A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.

A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.

▾ SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-73449Medium· 5.9
1w ago

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet throug…

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet throug…

▾ SunlitArista Networks · EOSEPSS 0.24%via NVD
Arista Networks vulnerabilities (CVEs) — page 2 · VulnSea