Vendor
Arista vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 50 vulnerabilities in Arista: 0 in the last 7 days and 45 in the last 90 days, 6 of them critical and 1 exploited in the wild. The most recent, CVE-2026-73462, was published on 16 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 45
- Critical, all time
- 6
- Exploited in the wild
- 1
About Arista
A networking technology company that designs and sells multilayer network switches and software-defined networking solutions.
Arista technologies
Latest Arista vulnerabilities
- CVE-2026-73462: Arista EOS IGMP snooping denial of service via malformed packetsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-73457: Arista EOS gNPSI credential logging in clear textmediumCVSS 5.3EPSS 0.3%
- CVE-2026-73456: Arista EOS gNPSI arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-73443: Arista EOS VRRPv2 IP-AH replay attack denial of servicemediumCVSS 4.7EPSS 0.3%
- CVE-2026-73442: Arista EOS VRRP credentials in cleartext logslowCVSS 3EPSS 0.2%
- CVE-2026-86107: Arista VeloCloud Edge and Gateway out-of-bounds write in VCMP tunnelmediumCVSS 5.9EPSS 0.4%
- CVE-2026-86106: Arista VeloCloud Edge HA authentication bypasscriticalCVSS 9.6EPSS 0.4%
- CVE-2026-77190: Arista EOS PIM Sparse Mode denial of servicemediumCVSS 6.5EPSS 0.3%
- CVE-2026-73469: Arista EOS loose uRPF verification bypassmediumCVSS 5.8EPSS 0.3%
- CVE-2026-73468: Arista EOS premature multicast state expiry in PIMmediumCVSS 6.5EPSS 0.3%
- CVE-2026-73455: Arista EOS OSPFv3 denial of service via crafted packethighCVSS 7.5EPSS 0.5%
- CVE-2026-73453: Arista EOS P4Runtime arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-73440: Arista EOS SNMPv3 credential exposure in configurationmediumCVSS 4.2EPSS 0.3%
- CVE-2026-73438: Arista EOS OSPFv3 agent denial of servicemediumCVSS 5.3EPSS 0.3%
- CVE-2026-73436: Arista EOS OSPFv2 segment routing denial of servicemediumCVSS 6.5EPSS 0.3%
- CVE-2026-73435: Arista EOS OSPFv2 authentication bypass causing adjacency flappinghighCVSS 8.2EPSS 0.2%
- CVE-2026-19640: Arista EOS gNMI incorrect authorization in OpenConfigmediumCVSS 4.2EPSS 0.2%
- CVE-2026-73464: Arista EOS code injection in gNMI interfacehighCVSS 8.8EPSS 0.6%
- CVE-2026-73463: Arista EOS gNSI Authz race condition authorization bypassmediumCVSS 5.3EPSS 0.2%
- CVE-2026-73461: Arista EOS incorrect privilege assignment in gRPC OpenConfighighCVSS 8EPSS 0.4%
- CVE-2026-73454: Arista EOS gNSI Credentialz privilege escalationhighCVSS 8.1EPSS 0.4%
- CVE-2026-73445: Arista EOS gNSI Authz Rotate RPC policy activation flawmediumCVSS 4.9EPSS 0.4%
- CVE-2026-73439: Arista EOS gNMI policy bypass via conflicting Pathz ruleshighCVSS 7.5EPSS 0.4%
- CVE-2026-2380: Arista EOS sensitive data logging in OpenConfig serviceshighCVSS 7.4EPSS 0.3%
- CVE-2026-73447: Arista EOS privilege escalation in gNSI CertzcriticalCVSS 9.1EPSS 0.7%
Most severe Arista vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-7473: Arista EOS improper tunnel protocol verification in decapsulationcriticalexploited in the wildCVSS 5.8EPSS 0.0%
- CVE-2026-73456: Arista EOS gNPSI arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-73453: Arista EOS P4Runtime arbitrary code executioncriticalCVSS 10EPSS 0.7%
- CVE-2026-86106: Arista VeloCloud Edge HA authentication bypasscriticalCVSS 9.6EPSS 0.4%
- CVE-2026-73437: Arista EOS DHCP relay source validation bypasscriticalCVSS 9.6EPSS 0.2%
- CVE-2026-73447: Arista EOS privilege escalation in gNSI CertzcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-73464: Arista EOS code injection in gNMI interfacehighCVSS 8.8EPSS 0.6%
- CVE-2016-9012: Arista CloudVision Portal access control bypass in management planehighCVSS 8.8
- CVE-2026-73458: Arista EOS BFD authentication bypass causing session resethighCVSS 8.2EPSS 0.4%
- CVE-2026-73435: Arista EOS OSPFv2 authentication bypass causing adjacency flappinghighCVSS 8.2EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 45 | 5 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/arista.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Arista vulnerabilities", https://junglewise.ai/threats/vendors/arista, 26 September 2026.