This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Project Subscriptions
No data.
No advisories yet.
Solution
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73469 has been fixed in the following releases: - 4.36.0F and later releases in the 4.36.x train - 4.35.5M and later releases in the 4.35.x train No hotfix is available for this issue.
Workaround
No mitigation exists for this issue.
Wed, 16 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | |
| Title | Security Advisory 0176 | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T10:13:40.801Z
Reserved: 2026-08-12T16:47:18.121Z
Link: CVE-2026-73469
No data.
Status : Received
Published: 2026-09-16T10:16:52.510
Modified: 2026-09-16T11:16:43.237
Link: CVE-2026-73469
No data.
OpenCVE Enrichment
No data.