ARISTA Networks on 9 September 2026 published four security advisories addressing multiple critical flaws in Arista EOS and VeloCloud Edge software. The disclosures describe unauthenticated and authenticated paths to arbitrary code execution, potentially giving an attacker full administrative control over affected switches and, in one case, VeloCloud Edge devices.
At present, there are no known in‑the‑wild exploits or public PoCs, and default configurations incidentally mitigate exposure by disabling the vulnerable interfaces.
The flaws span distinct management and control plane interfaces. CVE-2026-73456 (CVSS 10) involves a code‑injection risk in the gNPSI interface via unauthenticated gNPSI requests, while CVE-2026-73453 (CVSS 10) concerns the P4Runtime service via crafted packets during session initiation. CVE-2026-73447 (CVSS 9.1) enables operating system command execution through crafted certificate rotation requests by authenticated users.
CVE-2026-86106 (CVSS 9.6) affects VeloCloud Edge, where an unauthenticated attacker with local network access to the High Availability interconnect can trigger peer commands without verification. Affected EOS releases include 4.36.1F, 4.35.5M, 4.34.7M and earlier; VeloCloud Edge trains 6.4.x, 6.1.x and 5.2.x. Remediations include fixed EOS versions 4.36.2F, 4.35.6M, 4.34.8M and VeloCloud Edge 7.0.0 or 6.4.2.
If upgrading is not immediately feasible, mitigations such as mutual TLS with SPIFFE for gNPSI and P4Runtime, and direct port‑to‑port HA connections for VeloCloud, are advised.