CVE-2026-73464: Arista Networks Eos
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the switch.
Affected products
- Arista Networks Eos: from 4.29.0F, before 4.30.0F (fixed in 4.30.0F); from 4.30.0F, before 4.31.0F (fixed in 4.31.0F); from 4.31.0F, before 4.32.0F (fixed in 4.32.0F); from 4.32.0F, before 4.33.0F (fixed in 4.33.0F); from 4.33.0F, up to and including 4.33.8M; from 4.34.0F, up to and including 4.34.7M; …
Published 2026-09-16. Last modified 2026-09-17.