Arista EOS Vulnerability Still Active: Your Network Equipment Needs Attention Now

Share

If your business uses Arista switches, you need to know about CVE-2026-7473, a vulnerability in Arista Extensible Operating System (EOS) that has been actively exploited in the wild. This vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on June 9, 2026, and remains a serious threat months later. If you haven't patched yet, this is your reminder that the problem is still present and still being targeted.

What This Vulnerability Actually Does

Here's what matters: your Arista switch has a flaw in how it handles tunneled network packets. When a packet arrives with a destination IP that matches your switch's configured decapsulation IP address, the switch doesn't properly verify whether that packet should actually be decapsulated. Instead of checking all the factors it should, it processes certain unexpected tunneled packets anyway.

Think of it like a bouncer checking IDs at a door but only looking at the birthdate and ignoring the photo and name. An attacker can craft packets that look like they're supposed to be unwrapped at your switch, but aren't. The switch decapsulates them anyway and forwards them into your network. This breaks the security boundaries you thought your tunneling setup provided.

Why This Matters for Your Business

Network segmentation is a basic control. You probably have tunneled connections because you need to isolate traffic or connect remote locations securely. This vulnerability punches a hole in that isolation. An attacker doesn't need credentials or access to your internal network first—they just need to send specially crafted packets to your switch's decapsulation IP. Once those packets are forwarded inside your network, they can reach systems you thought were protected.

The deadline for action was June 23, 2026. We're past that now. The fact that you're reading this means either you've already patched and this is confirmation you made the right call, or you haven't yet and you're running on borrowed time.

Three Actions to Take This Week

Step One: Inventory Your Arista Equipment. Document which switches you own, their current EOS versions, and whether they use the decapsulation feature. Check your network documentation or contact whoever manages your switches. If you don't know what version you're running, log into your switches and check. This takes 30 minutes and prevents embarrassing gaps later.

Step Two: Apply Arista's Patch or Workaround. Visit Arista's support portal and download the fixed EOS version for your switch model. Arista has released patches for affected versions. If patching immediately isn't possible—because your switches can't be taken offline during business hours or for other operational reasons—apply whatever mitigation Arista provides in the meantime. Document what you've done and when you plan to complete the patch.

Step Three: Test and Deploy. Don't patch production switches without testing first. Use a lab environment or a non-critical switch to verify the patch doesn't break your tunneling configuration or other features. Then schedule the patching for your production environment during a maintenance window. Plan for a rollback if needed, though Arista patches are generally straightforward.

If You're Using Cloud-Based Arista Services

Follow the guidance in CISA's BOD 22-01 for federal systems. If you're not federal, the principle still applies: cloud service providers must patch on your behalf, but verify they have done so. Request documentation of patch status from your provider.

Sources

National Vulnerability Database Entry for CVE-2026-7473

CISA Known Exploited Vulnerabilities Catalog

Read more

Federal Contract Alert: Next Generation Ammunition & Munitions Equipment (NGAME) for MMHE RFP/Solicitation — DEPT OF DEFENSE.DEPT OF THE AIR FORCE.AIR FORCE MAT

NGAME MMHE RFP: What This Opportunity Actually Is The Air Force Life Cycle Management Center (AFLCMC) is seeking Next Generation Ammunition & Munitions Handling Equipment (NGAME) for Munitions Maintenance & Handling Equipment (MMHE). This is a production and/or engineering contract aimed at modernizing how the Air Force stores, transports,

By abdul wahib

Federal Contract Alert: J--Landing craft rehabilitation, Lake Roosevelt NRA. — INTERIOR, DEPARTMENT OF THE.NATIONAL PARK SERVICE.PWR OLYM MABO(83000)

What You're Looking At: Landing Craft Rehab at Lake Roosevelt The National Park Service (Power, Olympics & Mountaineer Area Office) is seeking a contractor to rehabilitate landing craft operated at Lake Roosevelt National Recreation Area in Washington State. This is straightforward marine vessel maintenance and repair work—hull

By abdul wahib