UNKNOWN Arista
CVE-2026-7473
Security Advisory 0137
Date: May 5, 2026
Revision
Date
Changes
1.0
May 5, 2026
Initial release
1.1
May 7, 2026
Clarified 7280R3, 7500R3 and 7800R3 exposure is limited
1.2
May 13, 2026
Updated Mitigation section with a note of caution
1.3
May 20, 2026
Updated Approach 2 - Applying ACL on Decapsulation Switches
The CVE-ID tracking this issue: CVE-2026-7473 CVSSv3.1 Base Score: 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N) CVSSv4.0 Base Score: 6.8 (CVSS:4.0/AV:N/AC:L/AT: ...
Affected Products
- CVE-2026-7473
References
- https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advi
- https://nvd.nist.gov/vuln/detail/CVE-2026-7473
This unknown severity vulnerability was published on 2026-05-05 via Arista. Affected: CVE-2026-7473.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.