CVE-2026-75943: Arista Networks Eos
Low severity, CVSS 2.6. EPSS: 0.2% chance of exploitation in the next 30 days.
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.
Affected products
- Arista Networks Eos: from 4.36.0, up to and including 4.36.1F; from 4.35.0, up to and including 4.35.5M; from 4.34.0, up to and including 4.34.7.1M; from 0.0.0, up to and including 4.33.9M
Published 2026-09-14. Last modified 2026-09-16.