CVE-2026-7473
CWE-1023Published: June 5, 2026· Updated: Jun 17, 2026
Official Description
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.
This issue has been reported as being exploited in the wild.
Risk Analysis
This medium-severity vulnerability in Arista EOS allows a switch to incorrectly decapsulate and forward unexpected tunneled packets. With a CVSS score of 5.8, this flaw can lead to unintended network traffic processing and potential information leakage. It is confirmed to be actively exploited, indicating a need for prompt attention.
This issue has been reported as being exploited in the wild. It is remotely exploitable over the network with low attack complexity and requires no authentication.
Review and adjust tunnel decapsulation configurations on Arista EOS devices. Ensure proper validation of tunnel protocol types to prevent unexpected traffic processing.
Technical Analysis
CVE-2026-7473 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.
CISA has added CVE-2026-7473 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.
CVSS v3.1 Vector Breakdown
Affected Vendors & Products
Exploit & PoC Resources
Official Patches & Advisories
News & Research Mentioning CVE-2026-7473
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures ( [xlite_meta score:54 src:CISA Alerts xlite_fp:f5c925405934f523e4a00a031732375aef6b8c3a722c3a629bc6338d0c644fc3]
All References (3)
Quick Facts
Related CVEs (CWE-1023)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-7473 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts
- !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
- !Active exploitation confirmed — treat as P1