CVE-2026-73458: Arista Networks Eos

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).

Affected products

  • Arista Networks Eos: from 4.36.0, up to and including 4.36.1F; from 4.35.0, up to and including 4.35.5M; from 4.34.0, up to and including 4.34.7M; from 4.33.0, up to and including 4.33.8M

Published 2026-09-15. Last modified 2026-09-16.