OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-73453

CRITICAL · CVSS 10 EPSS 0.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Arista EOS systems configured with P4Runtime are vulnerable to arbitrary code execution by unauthenticated clients, allowing attackers to gain full administrative control over affected switches. This critical vulnerability arises when a malicious packet is crafted during the initiation of a P4Runtime session, which is disabled by default. Organizations using Arista EOS with P4Runtime enabled should prioritize immediate remediation to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73453
Severity
CRITICAL
CVSS
10
EPSS
0.69%

Original NVD Description

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.