Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N N L N 6.9 .0111 63.3 YES
AFFECTED
Product Versions Fixed
EOS 4.36.0 – —
TIMELINE
Apr 29 Reserved by Arista
Jun 9 Added to CISA KEV, remediation due 2026-06-23
Jun 9 Published (CNA: Arista)
Jun 24 DUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog.
Description
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.
This issue has been reported as being exploited in the wild.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| April 29, 2026 | Reserved | Reserved by Arista |
| June 9, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-06-23 |
| June 9, 2026 | Published | Published (CNA: Arista) |
| June 24, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Arista Networks | EOS | — | 4.36.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-7473 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.