This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73469 has been fixed in the following releases: - 4.36.0F and later releases in the 4.36.x train - 4.35.5M and later releases in the 4.35.x train No hotfix is available for this issue.
Vendor Workaround
No mitigation exists for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | |
| Title | Security Advisory 0176 | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T13:41:36.781Z
Reserved: 2026-08-12T16:47:18.121Z
Link: CVE-2026-73469
Updated: 2026-09-16T13:41:32.256Z
Status : Received
Published: 2026-09-16T10:16:52.510
Modified: 2026-09-16T14:17:09.150
Link: CVE-2026-73469
No data.
OpenCVE Enrichment
No data.