What is CVE-2026-7473?
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
Timeline
- 2026-06-05Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-09Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-06-17NVD record last updated
- 2026-06-23CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Affected product
Arista Extensible Operating System
NVD also lists CPE entries for: Arista Eos, Arista 7020sr-24c2, Arista 7020sr-32c2, Arista 7020srg-24c2, Arista 7020tr-48
Remediation Steps
- Apply the vendor security update from Arista
- Review network device access logs for unauthorized activity
- Restrict management access to network devices from trusted administrative networks
References
- https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137
- https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7473
- https://nvd.nist.gov/vuln/detail/CVE-2026-7473
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of July 2026 (July 6 – 12)
- Vulnerability Priority Report – Week 5 of June 2026 (June 29 – July 5)
- Vulnerability Priority Report – Week 4 of June 2026 (June 22 – 28)
- Vulnerability Priority Report – Week 3 of June 2026 (June 15 – 21)
- Vulnerability Priority Report – Week 2 of June 2026 (June 8 – 14)
Browse all tracked CVEs in the defend.network CVE database →