CVE-2026-86106: Arista Networks VeloCloud Edge

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

Affected products

  • Arista Networks VeloCloud Edge: from 1.0.0.0, before 5.2.0.0 (fixed in 5.2.0.0); from 5.2.0.0, before 5.2.7.0 (fixed in 5.2.7.0); from 6.1.0.0, before 6.1.5.0 (fixed in 6.1.5.0); from 6.4.0.0, before 6.4.2.0 (fixed in 6.4.2.0)

Published 2026-09-16. Last modified 2026-09-16.