Skip to content
COOEY

FAIL › dossier

Arista

VENDOR

· dossier confidence 20%

Arista is a major cloud networking vendor whose recent high-severity vulnerabilities in its SD-WAN and EOS platforms have been actively exploited, including a CVSS 10.0 unauthenticated command injection in VeloCloud Orchestrator added to CISA's KEV catalogue.

PROFILE
CategorynetworkingWhat they doArista provides cloud networking solutions including the EOS operating system, CloudVision for automation, and SD-WAN/edge routing platforms. Websitehttps://www.arista.com ↗
SECURITY POSTURE

Arista has experienced high-severity unauthenticated command injection and packet misdecapsulation vulnerabilities in its SD-WAN and EOS platforms, with CVE-2026-16812 actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalogue.

Notable failures
  • CVE-2026-16812 unauthenticated command injection in VeloCloud Orchestrator
  • CVE-2026-7473 EOS packet misdecapsulation bypassing security controls
Patterns: unauthenticated command injection in management interfaces; incomplete validation in packet processing
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-07-27 CVE-2026-16812 high Arista's VeloCloud Orchestrator has a command injection vulnerability actively exploited in the wild, potentially granting attackers privileged access to internal systems and data managed by the orchestrator.
2026-06-09 CVE-2026-7473 high Arista EOS misdecapsulates tunneled packets due to an incomplete comparison vulnerability, enabling attackers to bypass security controls and potentially execute code on network devices.
Open questions: Arista's internal patching cadence for EOS and VeloCloud · Arista's incident response timeline for CVE-2026-16812 and CVE-2026-7473
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-15 03:59:04.643009+00:00