OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-73456

CRITICAL · CVSS 10 EPSS 0.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Arista EOS devices with the gRPC Network Packet Sampling Interface (gNPSI) enabled are vulnerable to unauthenticated remote code execution due to maliciously crafted requests. This critical vulnerability allows attackers to gain full administrative control over the affected switches, potentially compromising network integrity and security. Organizations utilizing Arista EOS with gNPSI should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73456
Severity
CRITICAL
CVSS
10
EPSS
0.69%

Original NVD Description

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.