Technology · Arista
Arista EOS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 49 vulnerabilities in Arista EOS: 0 in the last 7 days and 41 in the last 90 days, 7 of them critical and 1 exploited in the wild. The most recent, CVE-2026-73462, was published on 16 September 2026.
- Last 7 days
- 0
- Last 90 days
- 41
- Critical, all time
- 7
- Exploited in the wild
- 1
About Arista EOS
Arista EOS is a network operating system for data center and cloud networking switches.
Latest Arista EOS vulnerabilities
- CVE-2026-73462: Arista EOS IGMP snooping denial of service via malformed packetsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-73457: Arista EOS gNPSI credential logging in clear textmediumCVSS 5.3EPSS 0.3%
- CVE-2026-73456: Arista EOS gNPSI arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-73443: Arista EOS VRRPv2 IP-AH replay attack denial of servicemediumCVSS 4.7EPSS 0.3%
- CVE-2026-73442: Arista EOS VRRP credentials in cleartext logslowCVSS 3EPSS 0.2%
- CVE-2026-77190: Arista EOS PIM Sparse Mode denial of servicemediumCVSS 6.5EPSS 0.3%
- CVE-2026-73469: Arista EOS loose uRPF verification bypassmediumCVSS 5.8EPSS 0.3%
- CVE-2026-73468: Arista EOS premature multicast state expiry in PIMmediumCVSS 6.5EPSS 0.3%
- CVE-2026-73455: Arista EOS OSPFv3 denial of service via crafted packethighCVSS 7.5EPSS 0.5%
- CVE-2026-73453: Arista EOS P4Runtime arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-73440: Arista EOS SNMPv3 credential exposure in configurationmediumCVSS 4.2EPSS 0.3%
- CVE-2026-73438: Arista EOS OSPFv3 agent denial of servicemediumCVSS 5.3EPSS 0.3%
- CVE-2026-73436: Arista EOS OSPFv2 segment routing denial of servicemediumCVSS 6.5EPSS 0.3%
- CVE-2026-73435: Arista EOS OSPFv2 authentication bypass causing adjacency flappinghighCVSS 8.2EPSS 0.2%
- CVE-2026-19640: Arista EOS gNMI incorrect authorization in OpenConfigmediumCVSS 4.2EPSS 0.2%
- CVE-2026-73464: Arista EOS code injection in gNMI interfacehighCVSS 8.8EPSS 0.6%
- CVE-2026-73463: Arista EOS gNSI Authz race condition authorization bypassmediumCVSS 5.3EPSS 0.2%
- CVE-2026-73461: Arista EOS incorrect privilege assignment in gRPC OpenConfighighCVSS 8EPSS 0.4%
- CVE-2026-73454: Arista EOS gNSI Credentialz privilege escalationhighCVSS 8.1EPSS 0.4%
- CVE-2026-73445: Arista EOS gNSI Authz Rotate RPC policy activation flawmediumCVSS 4.9EPSS 0.4%
- CVE-2026-73439: Arista EOS gNMI policy bypass via conflicting Pathz ruleshighCVSS 7.5EPSS 0.4%
- CVE-2026-2380: Arista EOS sensitive data logging in OpenConfig serviceshighCVSS 7.4EPSS 0.3%
- CVE-2026-73447: Arista EOS privilege escalation in gNSI CertzcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-73450: Arista EOS MLAG dual-primary detection packet injectionmediumCVSS 6.9EPSS 0.2%
- CVE-2026-73460: Arista EOS IS-IS graceful restart denial of servicemediumCVSS 6.1EPSS 0.2%
Most severe Arista EOS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-7473: Arista EOS improper tunnel protocol verification in decapsulationcriticalexploited in the wildCVSS 5.8EPSS 0.0%
- CVE-2026-73456: Arista EOS gNPSI arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-73453: Arista EOS P4Runtime arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-73437: Arista EOS DHCP relay source validation bypasscriticalCVSS 9.6EPSS 0.2%
- CVE-2024-27892: Arista EOS unauthorized configuration change via gNMI Set in OpenConfigcriticalCVSS 9.6
- CVE-2024-27890: Arista EOS unauthorized configuration change via gNMI Set in OpenConfigcriticalCVSS 9.6
- CVE-2026-73447: Arista EOS privilege escalation in gNSI CertzcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-73464: Arista EOS code injection in gNMI interfacehighCVSS 8.8EPSS 0.6%
- CVE-2026-73458: Arista EOS BFD authentication bypass causing session resethighCVSS 8.2EPSS 0.4%
- CVE-2026-73435: Arista EOS OSPFv2 authentication bypass causing adjacency flappinghighCVSS 8.2EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 41 | 4 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/eos.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Arista EOS vulnerabilities", https://junglewise.ai/threats/technologies/eos, 26 September 2026.