Junglewise Threat Intelligence

CVE-2026-86107: Arista VeloCloud Edge and Gateway out-of-bounds write in VCMP tunnel

CVE-2026-86107 · Severity: medium · CVSS 5.9 · Published 2026-09-16

Executive brief

Arista VeloCloud Edge and Gateway devices, which are used to establish secure network tunnels and manage enterprise SD-WAN infrastructure, contain an out-of-bounds write vulnerability in their VCMP tunnel protocol. An authenticated attacker with an established peer relationship can send specially crafted IP fragments to crash the affected process, causing temporary network disruption until the service restarts. The vulnerability requires authentication and an established tunnel relationship, limiting exposure to trusted networks.

Technical details

This is an out-of-bounds write vulnerability (CWE-787) affecting VeloCloud Edge and Gateway when processing fragmented IP packets over authenticated VCMP tunnels between overlay peers. The root cause lies in improper bounds checking when reassembling tunneled IP fragments. Exploitation requires an authenticated VCMP tunnel to be established with a malicious VeloCloud Edge or Gateway peer, which then sends specifically malformed fragmented packets. A successful exploit causes the edged process (Edge) or gwd process (Gateway) to crash and restart, resulting in temporary traffic disruption. Patches are available in versions 7.0.0 and later, 6.4.2.0+, 6.1.5.0+, and 5.2.7.0+.

Affected products

  • Arista VeloCloud Edge 5.2.6.x and below, 6.1.4.x and below, 6.4.1.x and below
  • Arista VeloCloud Gateway 5.2.6.x and below, 6.1.4.x and below, 6.4.1.x and below

Timeline

  • 2026-09-09: disclosed: Security Advisory 0180 published
  • 2026-09-16: advisory: CVE-2026-86107 published

References

Related threats