CVE-2026-73462On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the I Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73457Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users. Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-73456Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Critical CVE-2026-73442On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Low CVE-2026-73443On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indef Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-86107Security Advisory 0180 Exploitation status Not known exploited Fix YesAffected product V VeloCloud Published 09/16/2026 Severity High CVE-2026-86106Security Advisory 0179 Exploitation status Not known exploited Fix YesAffected product V VeloCloud Edge Published 09/16/2026 Severity High CVE-2026-77190Security Advisory 0177 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-73468Security Advisory 0175 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73440Security Advisory 0178 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Low CVE-2026-73469Security Advisory 0176 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-73453Security Advisory 0174 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Critical CVE-2026-73455Security Advisory 0173 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73438Security Advisory 0172 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73436Security Advisory 0171 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-73435Security Advisory 0171 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-19640Security Advisory 0170 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Low CVE-2026-73463Security Advisory 0169 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-73445Security Advisory 0167 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-2380Security Advisory 0168 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Medium CVE-2026-73464Security Advisory 0166 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73454Security Advisory 0165 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73439Security Advisory 0164 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73461Security Advisory 0163 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Critical CVE-2026-73447Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity Critical CVE-2026-86109Security Advisory 0182 Exploitation status Not known exploited Fix YesAffected product V VeloCloud Edge Published 09/16/2026 Severity High CVE-2026-86108Security Advisory 0181 Exploitation status Not known exploited Fix YesAffected product V VeloCloud Edge Published 09/16/2026 Severity High CVE-2026-73450Security Advisory 0161 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/16/2026 Severity High CVE-2026-73460Security Advisory 0160 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity High CVE-2026-73459Security Advisory 0160 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity High CVE-2026-73446Security Advisory 0160 Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity High CVE-2026-73444On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Medium CVE-2026-73437On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper/destinat Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Medium CVE-2026-19655On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthent Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity High CVE-2026-73458On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Critical CVE-2026-73467On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Medium CVE-2026-73466On affected platforms running Arista EOS, under certain circumstances plaintext user passwords Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Medium CVE-2026-73465On affected platforms running Arista EOS, under certain circumstances plaintext private keys Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Medium CVE-2026-19641On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Medium CVE-2026-73451On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/15/2026 Severity Medium CVE-2026-75945A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/14/2026 Severity Low CVE-2026-75944A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/14/2026 Severity Medium CVE-2026-75943A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcem Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/14/2026 Severity Low CVE-2026-77191All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/14/2026 Severity Low CVE-2026-73449On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI Exploitation status Not known exploited Fix YesAffected product E EOS Published 09/14/2026 Severity Medium CVE-2026-17191VeloCloud Orchestrator Flow Metrics API SQL Injection Exploitation status Not known exploited Fix YesAffected product V VeloCloud Orchestrator On-Prem Published 07/27/2026 Severity High CVE-2026-17192VeloCloud Orchestrator Missing Input Validation SSRF Exploitation status Not known exploited Fix YesAffected product V VeloCloud Orchestrator On-Prem Published 07/27/2026 Severity Medium CVE-2026-16812VeloCloud Orchestrator OS Command Injection Exploitation status KEV Fix YesAffected product V VeloCloud Orchestrator On-Prem Published 07/27/2026 Severity Critical CVE-2026-25624Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Published 06/05/2026 Severity Medium CVE-2026-25623Arista Edge Threat Management NGFW UI Arbitrary Command Execution Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Published 06/05/2026 Severity High CVE-2026-25622Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Published 06/05/2026 Severity High CVE-2026-25621Arista Edge Threat Management NGFW Reports Application Insecure Input Validation Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Published 06/05/2026 Severity High CVE-2026-25620Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Published 06/05/2026 Severity High CVE-2026-2379Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled Exploitation status Not known exploited Fix YesAffected product E EOS Published 06/05/2026 Severity High CVE-2026-7473Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass Exploitation status KEV Fix YesAffected product E EOS Published 06/05/2026 Severity Medium CVE-2025-5088Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session Exploitation status Not known exploited Fix YesAffected product E EOS / CloudVision eXchange (CVX) Published 06/05/2026 Severity High CVE-2025-5090Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages Exploitation status Not known exploited Fix YesAffected product E EOS / CloudVision eXchange (CVX) Published 06/05/2026 Severity High CVE-2025-5089Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages Exploitation status Not known exploited Fix YesAffected product E EOS / CloudVision eXchange (CVX) Published 06/05/2026 Severity High CVE-2025-8873Arista EOS Dataplane Denial of Service via Malformed IPsec Packet Exploitation status Not known exploited Fix YesAffected product E EOS Published 06/04/2026 Severity High CVE-2023-5502On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication. Exploitation status Not known exploited Fix YesAffected product E EOS Published 06/04/2026 Severity High CVE-2024-27892On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled). Exploitation status Not known exploited Fix YesAffected product E EOS Published 06/04/2026 Severity High CVE-2024-27890On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled). Exploitation status Not known exploited Fix YesAffected product E EOS Published 06/04/2026 Severity High CVE-2024-27891On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. Exploitation status Not known exploited Fix YesAffected product E EOS Published 06/04/2026 Severity Medium CVE-2024-6858In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN. Exploitation status Not known exploited Fix YesAffected product E EOS Published 06/04/2026 Severity Medium CVE-2025-7048On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o Exploitation status Not known exploited Fix YesAffected product E EOS Published 01/06/2026 Severity Medium CVE-2025-8872A specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted Exploitation status Not known exploited Fix YesAffected product E EOS Published 12/16/2025 Severity High CVE-2025-8870On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device. Exploitation status Public exploit Fix YesAffected product E EOS Published 11/14/2025 Severity Medium CVE-2025-54549Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO Exploitation status Not known exploited Fix YesAffected product D DANZ Monitoring Fabric Published 10/29/2025 Severity Medium CVE-2025-54548On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes) Exploitation status Not known exploited Fix YesAffected product D DANZ Monitoring Fabric Published 10/29/2025 Severity Medium CVE-2025-54547On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired Exploitation status Not known exploited Fix YesAffected product D DANZ Monitoring Fabric Published 10/29/2025 Severity Medium CVE-2025-54546On affected platforms, restricted users could use SSH port forwarding to access host-internal services Exploitation status Not known exploited Fix YesAffected product D DANZ Monitoring Fabric Published 10/29/2025 Severity High CVE-2025-54545On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges. Exploitation status Not known exploited Fix YesAffected product D DANZ Monitoring Fabric Published 10/29/2025 Severity High CVE-2025-6978Diagnostics command injection vulnerability Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall Published 10/23/2025 Severity High CVE-2025-6979Captive Portal can allow authentication bypass Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall Published 10/23/2025 Severity High CVE-2025-6980Captive Portal can expose sensitive information Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management - Arista Next Generation Firewall Published 10/23/2025 Severity High CVE-2025-6188On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do n Exploitation status Not known exploited Fix YesAffected product E EOS Published 08/25/2025 Severity High CVE-2025-3456On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-c Exploitation status Not known exploited Fix YesAffected product E EOS Published 08/25/2025 Severity Low CVE-2025-2826n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. Exploitation status Not known exploited Fix YesAffected product E EOS Published 05/27/2025 Severity Low CVE-2025-2796On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal Exploitation status Not known exploited Fix YesAffected product E EOS Published 05/27/2025 Severity Medium CVE-2024-11185On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. Exploitation status Not known exploited Fix YesAffected product E EOS Published 05/27/2025 Severity Medium CVE-2024-9448On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropp Exploitation status Not known exploited Fix YesAffected product E EOS Published 05/08/2025 Severity High CVE-2024-12378On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear. Exploitation status Not known exploited Fix YesAffected product C CloudVision Portal Published 05/08/2025 Severity Critical CVE-2024-11186On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-prem Exploitation status Not known exploited Fix YesAffected product C CloudVision Portal Published 05/08/2025 Severity Critical CVE-2025-0505On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state Exploitation status Not known exploited Fix YesAffected product C CloudVision Portal Published 05/08/2025 Severity Critical CVE-2024-8100On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision. Exploitation status Not known exploited Fix YesAffected product C CloudVision Published 05/08/2025 Severity High CVE-2025-0936On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly Exploitation status Public exploit Fix YesAffected product E EOS Published 05/07/2025 Severity Medium CVE-2024-8000On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restar Exploitation status Not known exploited Fix YesAffected product E EOS Published 03/04/2025 Severity Medium CVE-2024-9135On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping. Exploitation status Not known exploited Fix YesAffected product E EOS Published 03/04/2025 Severity Medium CVE-2025-1260On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. Exploitation status Not known exploited Fix YesAffected product E EOS Published 03/04/2025 Severity Critical CVE-2025-1259On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. Exploitation status Not known exploited Fix YesAffected product E EOS Published 03/04/2025 Severity High CVE-2024-9188Specially constructed queries cause cross platform scripting leaking administrator tokens Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity High CVE-2024-47520A user with advanced report application access rights can perform actions for which they are not authorized Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity High CVE-2024-47519Backup uploads to ETM subject to man-in-the-middle interception Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity High CVE-2024-47518Specially constructed queries targeting ETM could discover active remote access sessions Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity Medium CVE-2024-47517Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity Medium CVE-2024-9134Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity High CVE-2024-9133A user with administrator privileges is able to retrieve authentication tokens Exploitation status Public exploit Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity Medium CVE-2024-9132The administrator is able to configure an insecure captive portal script Exploitation status Public exploit Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity High CVE-2024-9131A user with administrator privileges can perform command injection Exploitation status Not known exploited Fix YesAffected product A Arista Edge Threat Management Published 01/10/2025 Severity High CVE-2024-7142On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them Exploitation status Not known exploited Fix YesAffected product C CloudVision Appliance Published 01/10/2025 Severity Medium