Arista Networks
EOS
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
Official registry publication history is available at eos, but registry activity is not a publisher support boundary.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-73462 | 16 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.8M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73462 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.9M and later releases in the 4.33.x train | Update reference ↗ |
| CVE-2026-73457 | 16 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.2F ≤ 4.34.7M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73457 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train | Update reference ↗ |
| CVE-2026-73456 | 16 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.2F ≤ 4.34.7M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73456 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train | Update reference ↗ |
| CVE-2026-73442 | 16 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.9M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73442 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train | Update reference ↗ |
| CVE-2026-73443 | 16 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.9M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience.; Important: Upgrading alone is not sufficient. The replay protection introduced by the fix is disabled by default and must be explicitly enabled with the following new global configuration command after upgrading to a remediated release:; switch(config)#vrrp ipv4 authentication anti-replay; CVE-2026-73443 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train | Update reference ↗ |
| CVE-2026-77190 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.2F ≤ 4.34.7M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-77190 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73468 | 16 Sep 2026 | EOS: 1.0.0 < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7.1M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.1F | The following EOS releases contain the fix:; - 4.33.9M and later in the 4.33.x train; - 4.34.8M and later in the 4.34.x train; - 4.35.6M and later in the 4.35.x train; - 4.36.2F and later in the 4.36.x train; No hotfixes are available for this issue. | Update reference ↗ |
| CVE-2026-73440 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7.1M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; Following the system upgrade, users are required to execute the syntax conversion command specified below to adopt the updated, encrypted SNMPv3 CLI format:; switch# configure convert new-syntax; The updated encrypted SNMPv3 CLI configuration follows this structure, incorporating the newly introduced "key <algo> <encrypted_text>" syntax:; switch# show running-config | grep snmp-server; snmp-server user alice group_alice v3 localized f5717f2cdde9bb946d00 auth sha256 key 7 005D110205085E520B754E1B591C504542585F557D2F217064607A10034752035500080755575640440F5C00505053515F08525208035C1605525E0A040E781F4D; CVE-2026-73440 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73469 | 16 Sep 2026 | EOS: 4.35.0F ≤ 4.35.4M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73469 has been fixed in the following releases:; - 4.36.0F and later releases in the 4.36.x train; - 4.35.5M and later releases in the 4.35.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73453 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F < 4.34.0F, 4.32.0F < 4.33.0F, 4.31.0F < 4.32.0F, 4.30.0F < 4.31.0F, 4.29.2F < 4.30.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73453 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73455 | 16 Sep 2026 | EOS: 1.0.0 < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.6M, 4.35.0F ≤ 4.35.4M, 4.36.0F ≤ 4.36.0.1F | The following EOS releases contain the fix:; - 4.33.9M and later in the 4.33.x train; - 4.34.7M and later in the 4.34.x train; - 4.35.5M and later in the 4.35.x train; - 4.36.1F and later in the 4.36.x train; A hotfix (version 1.0) is available for 4.36.0.1F, 4.35.4M, 4.34.6M, and 4.33.8M. | Update reference ↗ |
| CVE-2026-73438 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73438 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73436 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7.1M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73436 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; No hotfix is available for CVE-2026-73436. | Update reference ↗ |
| CVE-2026-73435 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73435 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; A hotfix is available for the following releases: 4.36.1F, 4.35.5M, 4.34.7M, 4.33.9M.; URL: https://www.arista.com/support/advisories-notices/sa-download/?sa171-SecurityAdvisory171_CVE-2026-73435.swix; SWIX hash (SHA512): 4c4ff053d8165f347b45dfcafc2d20396e3eb00869b0088f3128be7f53b2a028b479fa8279849c800b5916ab9aaf8077718a68e3bf4277d55b44076650de0aa7; Note: Installing/uninstalling the SWIX will cause the Ospf process to restart. | Update reference ↗ |
| CVE-2026-19640 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.0.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.8M, 4.24.0F < 4.33.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-19640 has been fixed in the following releases:; - 4.36.1F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.9M and later releases in the 4.33.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73463 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.0.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.8M, 4.32.0F ≤ 4.32.11M, 4.31.0F ≤ 4.31.10M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73463 has been fixed in the following releases:; - 4.36.1F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.33.9M and later releases in the 4.33.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73445 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.0.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.8M, 4.32.0F < 4.33.0F, 4.31.0F < 4.32.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73445 has been fixed in the following releases:; - 4.36.1F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.9M and later releases in the 4.33.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-2380 | 16 Sep 2026 | EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F < 4.36.0F, 4.34.0F < 4.35.0F, 4.33.0F < 4.34.0F, < 4.33.0F | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-2380 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; No hotfix is available for this issue. | Update reference ↗ |
| CVE-2026-73464 | 16 Sep 2026 | EOS: 4.29.0F < 4.30.0F, 4.30.0F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F | The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. | Update reference ↗ |
| CVE-2026-73454 | 16 Sep 2026 | EOS: 4.30.0F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F | The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. | Update reference ↗ |
| CVE-2026-73439 | 16 Sep 2026 | EOS: 4.33.2F ≤ 4.33.8M, 4.34.0F ≤ 4.34.6M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F | The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. | Update reference ↗ |
| CVE-2026-73461 | 16 Sep 2026 | EOS: 4.29.0F < 4.30.0F, 4.30.0F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F ≤ 4.32.11M, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F | The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. | Update reference ↗ |
| CVE-2026-73447 | 16 Sep 2026 | EOS: 4.30.2F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F | The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. | Update reference ↗ |
| CVE-2026-73450 | 16 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M, 0.0.0 < 4.33.0 | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. | Update reference ↗ |
| CVE-2026-73460 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F | The recommended resolution is to upgrade to a fixed software version. | Update reference ↗ |
| CVE-2026-73459 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F | The recommended resolution is to upgrade to a fixed software version. | Update reference ↗ |
| CVE-2026-73446 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M, 4.32.0 < 4.33.0F, 4.31.0 < 4.32.0F | The recommended resolution is to upgrade to a fixed software version. | Update reference ↗ |
| CVE-2026-73444 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.9M, version range in vendor record | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73444 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train | Update reference ↗ |
| CVE-2026-73437 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience and enable the reply source-address validation CLI knob under dhcp relay mode:; switch(config)# dhcp relay; switch(config-dhcp-relay)# reply source-address validation; CVE-2026-73437 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train; Note: All versions require upgrading to a release containing the fix (as listed above) and applying the required configuration. Arista will not be providing any hotfixes. | Update reference ↗ |
| CVE-2026-19655 | 15 Sep 2026 | EOS: 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-19655 has been fixed in the following releases:; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train | Update reference ↗ |
| CVE-2026-73458 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.8M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.9M and later releases in the 4.33.x train | Update reference ↗ |
| CVE-2026-73467 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.7M, 0.0.0 ≤ 4.33.9M, ≤ 4.32.0, ≤ 4.31.0 | CVE-2026-73465 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. | Update reference ↗ |
| CVE-2026-73466 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.7M, 0.0.0 ≤ 4.33.9M, ≤ 4.32.0, ≤ 4.31.0 | CVE-2026-73465 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. | Update reference ↗ |
| CVE-2026-73465 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.7M, 0.0.0 ≤ 4.33.9M, ≤ 4.32.0, ≤ 4.31.0 | CVE-2026-73465 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. | Update reference ↗ |
| CVE-2026-19641 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.0F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 0.0.0 ≤ 4.33.8M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades.; CVE-2026-19641 has been fixed in the following releases:; * 4.36.1F and later releases in the 4.36.x train.; * 4.35.6M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.9M and later releases in the 4.33.x train. | Update reference ↗ |
| CVE-2026-73451 | 15 Sep 2026 | EOS: 4.36.0 ≤ 4.36.0.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.6M, 4.33.0 ≤ 4.33.8M, 4.32.0 ≤ 4.32.11M, 4.31.1F ≤ 4.31.10M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73451 has been fixed in the following releases:; * 4.36.1F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.7M and later releases in the 4.34.x train.; * 4.33.9M and later releases in the 4.33.x train. | Update reference ↗ |
| CVE-2026-75945 | 14 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F | CVE-2026-75945 has been fixed in the following release:; * 4.36.2F and later releases in the 4.36.x train. | Update reference ↗ |
| CVE-2026-75944 | 14 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F | CVE-2026-75944 has been fixed in the following release:; * 4.36.2F and later releases in the 4.36.x train. | Update reference ↗ |
| CVE-2026-75943 | 14 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 0.0.0 ≤ 4.33.9M | CVE-2026-75943 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.6M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. | Update reference ↗ |
| CVE-2026-77191 | 14 Sep 2026 | EOS: 4.35.0 ≤ 4.35.0.3F, 4.34.0 ≤ 4.34.5M, 0.0.0 ≤ 4.33.7.1M | CVE-2026-77191 has been fixed in the following releases:; * 4.35.1F and later releases in the 4.35.x train.; * 4.34.6M and later releases in the 4.34.x train.; * 4.33.8M and later releases in the 4.33.x train. | Update reference ↗ |
| CVE-2026-73449 | 14 Sep 2026 | EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73449 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train | Update reference ↗ |
| CVE-2026-2379 | 5 Jun 2026 | 4.34.0 ≤ 4.34.3M; 4.33.0M ≤ 4.33.5M; 4.32.0M ≤ 4.32.7M; 4.31.0M ≤ 4.31.9M; 4.30.0F < 4.31.0; 4.29.0F < 4.30.0; 4.28.0F < 4.29.0; 4.27.1F < 4.28.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-8873 | 4 Jun 2026 | 4.33.0M ≤ 4.33.4M; 4.32.0M ≤ 4.32.6.1M; 4.31.0M ≤ 4.31.7.1M; 4.30.0M ≤ 4.30.10M; 4.29.0M ≤ 4.29.10.1M | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-5502 | 4 Jun 2026 | 4.31.0 ≤ 4.31.0F; 4.30.0 ≤ 4.30.4M; 4.29.0 ≤ 4.29.6M; 4.28.0 ≤ 4.28.8M; 4.27.0 ≤ 4.27.11M; 4.26.0 ≤ 4.26.11M; 4.25.0 ≤ 4.25.11M; 4.24.0 ≤ 4.24.11M | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-27892 | 4 Jun 2026 | 4.31.0 ≤ 4.31.2F; 4.30.0 ≤ 4.30.5M; 4.29.0 ≤ 4.29.7M; 4.28.0 ≤ 4.28.10M; 4.27.0 ≤ 4.27.8M; 4.26.0 ≤ 4.26.9M; 4.25.0 ≤ 4.25.10M; 4.24.0 ≤ 4.24.11M | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-27890 | 4 Jun 2026 | 4.29.0 ≤ 4.29.7M; 4.28.0 ≤ 4.28.10M; 4.27.0 ≤ 4.27.8M; 4.26.0 ≤ 4.26.9M; 4.25.0 ≤ 4.25.10M; 4.24.0 ≤ 4.24.11M | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-27891 | 4 Jun 2026 | 4.32.0 ≤ 4.32.0.1F; 4.31.0 ≤ 4.31.2F; 4.30.0 ≤ 4.30.6M; 4.29.0 ≤ 4.29.7M; 4.28.0 ≤ 4.28.10.1M; 4.27.2F < 4.28.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-6858 | 4 Jun 2026 | 4.31.0 ≤ 4.31.1F; 4.30.0 ≤ 4.30.5M; 4.29.0 ≤ 4.29.7M; 4.28.10 ≤ 4.28.10.1M | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-7048 | 6 Jan 2026 | EOS: 4.34.3.0 ≤ 4.34.3.1M, 4.33.0 ≤ 4.33.5M, 4.32.0 ≤ 4.32.7M, 4.31.0 ≤ 4.31.9M, < 4.30.0 | The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; For more information about upgrading see EOS User Manual: Upgrades and Downgrades https://www.arista.com/en/um-eos/eos-upgrades-and-downgrades; CVE-2025-7048 has been fixed in the following releases:; * 4.35.0F and later releases; * 4.34.4M and later releases in the 4.34.x train; * 4.33.6M and later releases in the 4.33.x train; * 4.32.8M and later releases in the 4.32.x train; * 4.31.10M and later releases in the 4.31.x train | Update reference ↗ |
| CVE-2025-8872 | 16 Dec 2025 | 4.34.0 ≤ 4.34.1F; 4.33.0 ≤ 4.33.4M; 4.32.0 ≤ 4.32.7M; 4.31.0 ≤ 4.31.8M; ≤ 4.31.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.