CVE-2026-77191: Arista Networks Eos

Low severity, CVSS 2.6. EPSS: 0.2% chance of exploitation in the next 30 days.

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.

Affected products

  • Arista Networks Eos: from 4.35.0, up to and including 4.35.0.3F; from 4.34.0, up to and including 4.34.5M; from 0.0.0, up to and including 4.33.7.1M

Published 2026-09-14. Last modified 2026-09-16.