CISA has added CVE-2026-7473, a tunnel-decapsulation flaw in Arista's Extensible Operating System (EOS), to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild.
What Is It
CVE-2026-7473 is an "incomplete comparison with missing factors" weakness (CWE-1023) in Arista EOS. On switches configured for tunnel decapsulation, such as VXLAN, decap-groups, or a GRE tunnel interface, the device fails to verify the tunnel protocol type. As a result, it will incorrectly decapsulate and forward unexpected tunneled packets whose destination IP matches its configured decapsulation IP, leading to processing of non-configured tunnel traffic.
Why It Matters
The flaw is network-reachable with low attack complexity and requires no privileges or user interaction (CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N). NVD scores it 5.8 (MEDIUM); Arista's CVSS 4.0 assessment rates it 6.9 (MEDIUM). Impact is limited to low integrity effects, but the scope is "changed"; meaning improperly forwarded traffic can reach beyond the switch's intended boundary. Critically, both Arista and NVD note the issue has been reported as exploited in the wild, and CISA's KEV listing confirms active exploitation.
What's Vulnerable
Affected platforms run Arista EOS with a tunnel decapsulation configuration present (VXLAN, decap-groups, or GRE). The vulnerability applies to EOS itself (cpe:2.3:o:arista:eos), with the advisory enumerating a broad range of affected hardware including the Arista 7020 and 7280 series switches. Devices without a tunnel decapsulation configuration are not in the exploitable path.
Patch Status
CISA's required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. The remediation due date for federal agencies is 2026-06-23. Administrators should consult Arista Security Advisory 0137 for specific fixed versions and mitigation steps. Known ransomware campaign use is listed as Unknown.
Sources
- Arista Security Advisory 0137; https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137
- NVD, CVE-2026-7473, https://nvd.nist.gov/vuln/detail/CVE-2026-7473
- CISA KEV Catalog, CVE-2026-7473, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7473