{"schema_version":1,"title":"Arista vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 50 vulnerabilities in Arista: 0 in the last 7 days and 45 in the last 90 days, 6 of them critical and 1 exploited in the wild. The most recent, CVE-2026-73462, was published on 16 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/arista","json_url":"https://junglewise.ai/threats/vendors/arista.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/arista","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":13,"all_time":50,"critical":6,"exploited":1,"last_7_days":0,"last_30_days":45,"last_90_days":45,"last_365_days":49},"latest":[{"cve":"CVE-2026-73462","cvss":6.5,"epss":0.0028,"slug":"cve-2026-73462-arista-eos-igmp-snooping-denial-of-service-via-malformed-packets","title":"Arista EOS IGMP snooping denial of service via malformed packets","severity":"medium","exploited":false,"published_at":"2026-09-16T19:17:32.63+00:00","url":"https://junglewise.ai/threats/cve-2026-73462-arista-eos-igmp-snooping-denial-of-service-via-malformed-packets"},{"cve":"CVE-2026-73457","cvss":5.3,"epss":0.0032,"slug":"cve-2026-73457-arista-eos-gnpsi-credential-logging-in-clear-text","title":"Arista EOS gNPSI credential logging in clear text","severity":"medium","exploited":false,"published_at":"2026-09-16T19:17:32.453+00:00","url":"https://junglewise.ai/threats/cve-2026-73457-arista-eos-gnpsi-credential-logging-in-clear-text"},{"cve":"CVE-2026-73456","cvss":10,"epss":0.007,"slug":"cve-2026-73456-arista-eos-gnpsi-arbitrary-code-execution","title":"Arista EOS gNPSI arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-16T19:17:32.27+00:00","url":"https://junglewise.ai/threats/cve-2026-73456-arista-eos-gnpsi-arbitrary-code-execution"},{"cve":"CVE-2026-73443","cvss":4.7,"epss":0.0027,"slug":"cve-2026-73443-arista-eos-vrrpv2-ip-ah-replay-attack-denial-of-service","title":"Arista EOS VRRPv2 IP-AH replay attack denial of service","severity":"medium","exploited":false,"published_at":"2026-09-16T19:17:31.33+00:00","url":"https://junglewise.ai/threats/cve-2026-73443-arista-eos-vrrpv2-ip-ah-replay-attack-denial-of-service"},{"cve":"CVE-2026-73442","cvss":3,"epss":0.0021,"slug":"cve-2026-73442-arista-eos-vrrp-credentials-in-cleartext-logs","title":"Arista EOS VRRP credentials in cleartext logs","severity":"low","exploited":false,"published_at":"2026-09-16T19:17:31.08+00:00","url":"https://junglewise.ai/threats/cve-2026-73442-arista-eos-vrrp-credentials-in-cleartext-logs"},{"cve":"CVE-2026-86107","cvss":5.9,"epss":0.0037,"slug":"cve-2026-86107-arista-velocloud-edge-and-gateway-out-of-bounds-write-in-vcmp","title":"Arista VeloCloud Edge and Gateway out-of-bounds write in VCMP tunnel","severity":"medium","exploited":false,"published_at":"2026-09-16T11:16:43.92+00:00","url":"https://junglewise.ai/threats/cve-2026-86107-arista-velocloud-edge-and-gateway-out-of-bounds-write-in-vcmp"},{"cve":"CVE-2026-86106","cvss":9.6,"epss":0.0036,"slug":"cve-2026-86106-arista-velocloud-edge-ha-authentication-bypass","title":"Arista VeloCloud Edge HA authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-16T11:16:43.783+00:00","url":"https://junglewise.ai/threats/cve-2026-86106-arista-velocloud-edge-ha-authentication-bypass"},{"cve":"CVE-2026-77190","cvss":6.5,"epss":0.0028,"slug":"cve-2026-77190-arista-eos-pim-sparse-mode-denial-of-service","title":"Arista EOS PIM Sparse Mode denial of service","severity":"medium","exploited":false,"published_at":"2026-09-16T10:16:53.03+00:00","url":"https://junglewise.ai/threats/cve-2026-77190-arista-eos-pim-sparse-mode-denial-of-service"},{"cve":"CVE-2026-73469","cvss":5.8,"epss":0.0029,"slug":"cve-2026-73469-arista-eos-loose-urpf-verification-bypass","title":"Arista EOS loose uRPF verification bypass","severity":"medium","exploited":false,"published_at":"2026-09-16T10:16:52.51+00:00","url":"https://junglewise.ai/threats/cve-2026-73469-arista-eos-loose-urpf-verification-bypass"},{"cve":"CVE-2026-73468","cvss":6.5,"epss":0.0029,"slug":"cve-2026-73468-arista-eos-premature-multicast-state-expiry-in-pim","title":"Arista EOS premature multicast state expiry in PIM","severity":"medium","exploited":false,"published_at":"2026-09-16T10:16:52.383+00:00","url":"https://junglewise.ai/threats/cve-2026-73468-arista-eos-premature-multicast-state-expiry-in-pim"},{"cve":"CVE-2026-73455","cvss":7.5,"epss":0.005,"slug":"cve-2026-73455-arista-eos-ospfv3-denial-of-service-via-crafted-packet","title":"Arista EOS OSPFv3 denial of service via crafted packet","severity":"high","exploited":false,"published_at":"2026-09-16T10:16:52.243+00:00","url":"https://junglewise.ai/threats/cve-2026-73455-arista-eos-ospfv3-denial-of-service-via-crafted-packet"},{"cve":"CVE-2026-73453","cvss":10,"epss":0.007,"slug":"cve-2026-73453-arista-eos-p4runtime-arbitrary-code-execution","title":"Arista EOS P4Runtime arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-16T10:16:52.043+00:00","url":"https://junglewise.ai/threats/cve-2026-73453-arista-eos-p4runtime-arbitrary-code-execution"},{"cve":"CVE-2026-73440","cvss":4.2,"epss":0.0027,"slug":"cve-2026-73440-arista-eos-snmpv3-credential-exposure-in-configuration","title":"Arista EOS SNMPv3 credential exposure in configuration","severity":"medium","exploited":false,"published_at":"2026-09-16T10:16:51.87+00:00","url":"https://junglewise.ai/threats/cve-2026-73440-arista-eos-snmpv3-credential-exposure-in-configuration"},{"cve":"CVE-2026-73438","cvss":5.3,"epss":0.0025,"slug":"cve-2026-73438-arista-eos-ospfv3-agent-denial-of-service","title":"Arista EOS OSPFv3 agent denial of service","severity":"medium","exploited":false,"published_at":"2026-09-16T10:16:51.69+00:00","url":"https://junglewise.ai/threats/cve-2026-73438-arista-eos-ospfv3-agent-denial-of-service"},{"cve":"CVE-2026-73436","cvss":6.5,"epss":0.0027,"slug":"cve-2026-73436-arista-eos-ospfv2-segment-routing-denial-of-service","title":"Arista EOS OSPFv2 segment routing denial of service","severity":"medium","exploited":false,"published_at":"2026-09-16T10:16:51.55+00:00","url":"https://junglewise.ai/threats/cve-2026-73436-arista-eos-ospfv2-segment-routing-denial-of-service"},{"cve":"CVE-2026-73435","cvss":8.2,"epss":0.0019,"slug":"cve-2026-73435-arista-eos-ospfv2-authentication-bypass-causing-adjacency","title":"Arista EOS OSPFv2 authentication bypass causing adjacency flapping","severity":"high","exploited":false,"published_at":"2026-09-16T10:16:51.363+00:00","url":"https://junglewise.ai/threats/cve-2026-73435-arista-eos-ospfv2-authentication-bypass-causing-adjacency"},{"cve":"CVE-2026-19640","cvss":4.2,"epss":0.0019,"slug":"cve-2026-19640-arista-eos-gnmi-incorrect-authorization-in-openconfig","title":"Arista EOS gNMI incorrect authorization in OpenConfig","severity":"medium","exploited":false,"published_at":"2026-09-16T10:16:50.943+00:00","url":"https://junglewise.ai/threats/cve-2026-19640-arista-eos-gnmi-incorrect-authorization-in-openconfig"},{"cve":"CVE-2026-73464","cvss":8.8,"epss":0.0064,"slug":"cve-2026-73464-arista-eos-code-injection-in-gnmi-interface","title":"Arista EOS code injection in gNMI interface","severity":"high","exploited":false,"published_at":"2026-09-16T09:17:05.463+00:00","url":"https://junglewise.ai/threats/cve-2026-73464-arista-eos-code-injection-in-gnmi-interface"},{"cve":"CVE-2026-73463","cvss":5.3,"epss":0.0021,"slug":"cve-2026-73463-arista-eos-gnsi-authz-race-condition-authorization-bypass","title":"Arista EOS gNSI Authz race condition authorization bypass","severity":"medium","exploited":false,"published_at":"2026-09-16T09:17:05.3+00:00","url":"https://junglewise.ai/threats/cve-2026-73463-arista-eos-gnsi-authz-race-condition-authorization-bypass"},{"cve":"CVE-2026-73461","cvss":8,"epss":0.0039,"slug":"cve-2026-73461-arista-eos-incorrect-privilege-assignment-in-grpc-openconfig","title":"Arista EOS incorrect privilege assignment in gRPC OpenConfig","severity":"high","exploited":false,"published_at":"2026-09-16T09:17:05.147+00:00","url":"https://junglewise.ai/threats/cve-2026-73461-arista-eos-incorrect-privilege-assignment-in-grpc-openconfig"},{"cve":"CVE-2026-73454","cvss":8.1,"epss":0.0039,"slug":"cve-2026-73454-arista-eos-gnsi-credentialz-privilege-escalation","title":"Arista EOS gNSI Credentialz privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-16T09:17:05.02+00:00","url":"https://junglewise.ai/threats/cve-2026-73454-arista-eos-gnsi-credentialz-privilege-escalation"},{"cve":"CVE-2026-73445","cvss":4.9,"epss":0.0035,"slug":"cve-2026-73445-arista-eos-gnsi-authz-rotate-rpc-policy-activation-flaw","title":"Arista EOS gNSI Authz Rotate RPC policy activation flaw","severity":"medium","exploited":false,"published_at":"2026-09-16T09:17:04.853+00:00","url":"https://junglewise.ai/threats/cve-2026-73445-arista-eos-gnsi-authz-rotate-rpc-policy-activation-flaw"},{"cve":"CVE-2026-73439","cvss":7.5,"epss":0.0036,"slug":"cve-2026-73439-arista-eos-gnmi-policy-bypass-via-conflicting-pathz-rules","title":"Arista EOS gNMI policy bypass via conflicting Pathz rules","severity":"high","exploited":false,"published_at":"2026-09-16T09:17:04.687+00:00","url":"https://junglewise.ai/threats/cve-2026-73439-arista-eos-gnmi-policy-bypass-via-conflicting-pathz-rules"},{"cve":"CVE-2026-2380","cvss":7.4,"epss":0.0025,"slug":"cve-2026-2380-arista-eos-sensitive-data-logging-in-openconfig-services","title":"Arista EOS sensitive data logging in OpenConfig services","severity":"high","exploited":false,"published_at":"2026-09-16T09:17:04.483+00:00","url":"https://junglewise.ai/threats/cve-2026-2380-arista-eos-sensitive-data-logging-in-openconfig-services"},{"cve":"CVE-2026-73447","cvss":9.1,"epss":0.0071,"slug":"cve-2026-73447-arista-eos-privilege-escalation-in-gnsi-certz","title":"Arista EOS privilege escalation in gNSI Certz","severity":"critical","exploited":false,"published_at":"2026-09-16T07:16:37.087+00:00","url":"https://junglewise.ai/threats/cve-2026-73447-arista-eos-privilege-escalation-in-gnsi-certz"}],"vendor":{"hub":true,"name":"Arista","slug":"arista","homepage":"https://www.arista.com/","description":"A networking technology company that designs and sells multilayer network switches and software-defined networking solutions.","url":"https://junglewise.ai/threats/vendors/arista"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":5,"exploited":0,"vulnerabilities":45},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-7473","cvss":5.8,"epss":0.0003,"slug":"cve-2026-7473-arista-eos-improper-tunnel-protocol-verification-in-decapsulation","title":"Arista EOS improper tunnel protocol verification in decapsulation","severity":"critical","exploited":true,"published_at":"2026-06-05T17:17:02.85+00:00","url":"https://junglewise.ai/threats/cve-2026-7473-arista-eos-improper-tunnel-protocol-verification-in-decapsulation"},{"cve":"CVE-2026-73456","cvss":10,"epss":0.007,"slug":"cve-2026-73456-arista-eos-gnpsi-arbitrary-code-execution","title":"Arista EOS gNPSI arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-16T19:17:32.27+00:00","url":"https://junglewise.ai/threats/cve-2026-73456-arista-eos-gnpsi-arbitrary-code-execution"},{"cve":"CVE-2026-73453","cvss":10,"epss":0.007,"slug":"cve-2026-73453-arista-eos-p4runtime-arbitrary-code-execution","title":"Arista EOS P4Runtime arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-16T10:16:52.043+00:00","url":"https://junglewise.ai/threats/cve-2026-73453-arista-eos-p4runtime-arbitrary-code-execution"},{"cve":"CVE-2026-86106","cvss":9.6,"epss":0.0036,"slug":"cve-2026-86106-arista-velocloud-edge-ha-authentication-bypass","title":"Arista VeloCloud Edge HA authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-16T11:16:43.783+00:00","url":"https://junglewise.ai/threats/cve-2026-86106-arista-velocloud-edge-ha-authentication-bypass"},{"cve":"CVE-2026-73437","cvss":9.6,"epss":0.0021,"slug":"cve-2026-73437-arista-eos-dhcp-relay-source-validation-bypass","title":"Arista EOS DHCP relay source validation bypass","severity":"critical","exploited":false,"published_at":"2026-09-15T22:16:58.22+00:00","url":"https://junglewise.ai/threats/cve-2026-73437-arista-eos-dhcp-relay-source-validation-bypass"},{"cve":"CVE-2026-73447","cvss":9.1,"epss":0.0071,"slug":"cve-2026-73447-arista-eos-privilege-escalation-in-gnsi-certz","title":"Arista EOS privilege escalation in gNSI Certz","severity":"critical","exploited":false,"published_at":"2026-09-16T07:16:37.087+00:00","url":"https://junglewise.ai/threats/cve-2026-73447-arista-eos-privilege-escalation-in-gnsi-certz"},{"cve":"CVE-2026-73464","cvss":8.8,"epss":0.0064,"slug":"cve-2026-73464-arista-eos-code-injection-in-gnmi-interface","title":"Arista EOS code injection in gNMI interface","severity":"high","exploited":false,"published_at":"2026-09-16T09:17:05.463+00:00","url":"https://junglewise.ai/threats/cve-2026-73464-arista-eos-code-injection-in-gnmi-interface"},{"cve":"CVE-2016-9012","cvss":8.8,"slug":"cve-2016-9012-arista-cloudvision-portal-access-control-bypass-in-management","title":"Arista CloudVision Portal access control bypass in management plane","severity":"high","exploited":false,"published_at":"2017-01-23T21:59:02.643+00:00","url":"https://junglewise.ai/threats/cve-2016-9012-arista-cloudvision-portal-access-control-bypass-in-management"},{"cve":"CVE-2026-73458","cvss":8.2,"epss":0.004,"slug":"cve-2026-73458-arista-eos-bfd-authentication-bypass-causing-session-reset","title":"Arista EOS BFD authentication bypass causing session reset","severity":"high","exploited":false,"published_at":"2026-09-15T20:17:43.16+00:00","url":"https://junglewise.ai/threats/cve-2026-73458-arista-eos-bfd-authentication-bypass-causing-session-reset"},{"cve":"CVE-2026-73435","cvss":8.2,"epss":0.0019,"slug":"cve-2026-73435-arista-eos-ospfv2-authentication-bypass-causing-adjacency","title":"Arista EOS OSPFv2 authentication bypass causing adjacency flapping","severity":"high","exploited":false,"published_at":"2026-09-16T10:16:51.363+00:00","url":"https://junglewise.ai/threats/cve-2026-73435-arista-eos-ospfv2-authentication-bypass-causing-adjacency"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Arista EOS","slug":"eos","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/eos"},{"name":"Arista Velocloud Edge","slug":"velocloud-edge","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/velocloud-edge"}]}