Arista Networks published four security advisories on September 9, 2026, resolving multiple critical security flaws. These critical Arista EOS vulnerabilities allow unauthenticated attackers to execute arbitrary code and seize control of enterprise switches. Currently, researchers have observed no active in-the-wild exploitation or public proof-of-concept exploits for these flaws.
Why This Matters
Industry estimates indicate that thousands of data centers and cloud providers deploy Arista hardware globally. As a result, critical flaws in switch operating systems pose a severe threat to network backbones. If attackers exploit these Arista EOS vulnerabilities, they can gain administrative privileges over core switching gear. Consequently, unauthorized users could intercept traffic, disrupt services, or pivot deeper into internal environments.
How the Attack Works
The vulnerabilities target different network management and control plane interfaces. The first critical flaw, CVE-2026-73456 (CVSS 10), involves a code injection bug in the gRPC Network Packet Sampling Interface. According to the advisory, “Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.”
Furthermore, CVE-2026-73453 (CVSS 10) targets the P4Runtime service. The advisory notes, “By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch.” Meanwhile, CVE-2026-73447 (CVSS 9.1) permits authenticated users to execute operating system commands via crafted certificate rotation requests. Finally, CVE-2026-86106 (CVSS 9.6) affects VeloCloud Edge devices. An unauthenticated attacker with local network access to the High Availability interconnect can trigger peer commands without verification.
Affected Versions
These vulnerabilities impact numerous EOS release trains. Specifically, versions 4.36.1F, 4.35.5M, and 4.34.7M and earlier releases contain vulnerable components. Additionally, the VeloCloud Edge flaw affects software trains 6.4.x, 6.1.x, and 5.2.x. Fortunately, default configurations disable both gNPSI and P4Runtime, which limits immediate exposure.
Patch and Mitigation Steps
Arista discovered all issues internally and reports no malicious use in customer networks. Furthermore, no public proof-of-concept exploit code exists. Network administrators should immediately update their systems to remediated releases. Fixed versions include EOS 4.36.2F, 4.35.6M, 4.34.8M, and VeloCloud Edge 7.0.0 or 6.4.2.
If immediate upgrading is difficult, administrators should apply available workarounds. For instance, teams can enforce mutual TLS with SPIFFE authentication for gNPSI and P4Runtime. For VeloCloud Edge devices, administrators must use direct port-to-port connections for the High Availability pair. You can review all advisories in the Arista security advisory portal.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!