When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.

This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73469 has been fixed in the following releases: - 4.36.0F and later releases in the 4.36.x train - 4.35.5M and later releases in the 4.35.x train No hotfix is available for this issue.


Workaround

No mitigation exists for this issue.

History

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Title Security Advisory 0176
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T10:13:40.801Z

Reserved: 2026-08-12T16:47:18.121Z

Link: CVE-2026-73469

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T10:16:52.510

Modified: 2026-09-16T11:16:43.237

Link: CVE-2026-73469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses