Arista EOS Vulnerability Still Active: Your Network Equipment Needs Attention Now
If your business uses Arista switches, you need to know about CVE-2026-7473, a vulnerability in Arista Extensible Operating System (EOS) that has been actively exploited in the wild. This vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on June 9, 2026, and remains a serious threat months later. If you haven't patched yet, this is your reminder that the problem is still present and still being targeted.
What This Vulnerability Actually Does
Here's what matters: your Arista switch has a flaw in how it handles tunneled network packets. When a packet arrives with a destination IP that matches your switch's configured decapsulation IP address, the switch doesn't properly verify whether that packet should actually be decapsulated. Instead of checking all the factors it should, it processes certain unexpected tunneled packets anyway.
Think of it like a bouncer checking IDs at a door but only looking at the birthdate and ignoring the photo and name. An attacker can craft packets that look like they're supposed to be unwrapped at your switch, but aren't. The switch decapsulates them anyway and forwards them into your network. This breaks the security boundaries you thought your tunneling setup provided.
Why This Matters for Your Business
Network segmentation is a basic control. You probably have tunneled connections because you need to isolate traffic or connect remote locations securely. This vulnerability punches a hole in that isolation. An attacker doesn't need credentials or access to your internal network first—they just need to send specially crafted packets to your switch's decapsulation IP. Once those packets are forwarded inside your network, they can reach systems you thought were protected.
The deadline for action was June 23, 2026. We're past that now. The fact that you're reading this means either you've already patched and this is confirmation you made the right call, or you haven't yet and you're running on borrowed time.
Three Actions to Take This Week
Step One: Inventory Your Arista Equipment. Document which switches you own, their current EOS versions, and whether they use the decapsulation feature. Check your network documentation or contact whoever manages your switches. If you don't know what version you're running, log into your switches and check. This takes 30 minutes and prevents embarrassing gaps later.
Step Two: Apply Arista's Patch or Workaround. Visit Arista's support portal and download the fixed EOS version for your switch model. Arista has released patches for affected versions. If patching immediately isn't possible—because your switches can't be taken offline during business hours or for other operational reasons—apply whatever mitigation Arista provides in the meantime. Document what you've done and when you plan to complete the patch.
Step Three: Test and Deploy. Don't patch production switches without testing first. Use a lab environment or a non-critical switch to verify the patch doesn't break your tunneling configuration or other features. Then schedule the patching for your production environment during a maintenance window. Plan for a rollback if needed, though Arista patches are generally straightforward.
If You're Using Cloud-Based Arista Services
Follow the guidance in CISA's BOD 22-01 for federal systems. If you're not federal, the principle still applies: cloud service providers must patch on your behalf, but verify they have done so. Request documentation of patch status from your provider.