CVE-2026-7473: Arista Extensible Operating System
EPSS0.6%No. 1708 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV3
Same product1
| Field | Value |
|---|---|
| Vendor | Arista |
| Product | Extensible Operating System |
| Name | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability |
| Added to KEV | 2026-06-09 |
| US federal due date | 2026-06-23 |
| Ransomware use | Unknown |
| CWE | CWE-1023 |
CISA description
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Arista Extensible Operating System vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-09.