Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Arista refuses to patch KEV flaw

3 min read
12:09UTC

Arista Networks told customers it has no plans to fix CVE-2026-7473, an exploited tunnel-verification flaw on CISA's mandatory-remediation list, leaving federal agencies legally bound to fix something the vendor will not.

TechnologyDeveloping
Key takeaway

Arista is the first vendor to formally refuse a fix for a flaw on CISA's mandatory-remediation list.

Arista Networks told customers it has no plans to ship a fix for CVE-2026-7473, a CVSS 6.9 tunnel-verification flaw in Arista EOS (Extensible Operating System) that CISA added to its KEV (Known Exploited Vulnerabilities) catalogue on 9 June with a 23 June federal deadline 1. Affected switches configured to unwrap one tunnel type wrongly accept others instead; Arista says a code fix would break working configurations on its 7020R, 7280R and 7500R series, and offers access-control lists only. Federal agencies are now legally bound to remediate a flaw the vendor will not repair.

The KEV catalogue is CISA's list of vulnerabilities confirmed under active attack; once a flaw lands on it, US federal civilian agencies must close it by a set date. That model assumes a patch exists, or soon will. This is the second time in six weeks that the assumption has failed. The Exchange OWA flaw carried a 29 May cut-off with no fix available , and PAN-OS had a deadline land four days before its patch . Arista is the worse case of the three, because Exchange and PAN-OS merely ran late while Arista formally declines to ship anything.

BOD 22-01 (Binding Operational Directive 22-01), the November 2021 order behind the KEV catalogue, has no provision for a vendor that refuses to patch. Its remediation clock presumes the fix is the bottleneck, not the vendor's willingness to write one. The same 9 June batch added a Chrome V8 RCE (Remote Code Execution) and the seventh Cisco SD-WAN KEV entry of 2026, so the listing tempo is not slowing. For an agency running Arista in production, the only route to compliance by 23 June is network access-control lists and change-management cycles, which take longer and leave gaps a patch would not.

Deep Analysis

In plain English

Arista Networks makes the high-speed network switches used to route data traffic inside large data centres. A security flaw called CVE-2026-7473 was found in Arista's switch software that allows an attacker to send disguised network packets that the switch handles incorrectly. The US government's CISA agency added this flaw to its official must-fix list on 9 June, giving federal agencies until 23 June to address it. The unusual part: Arista told CISA that it will never release a software fix. The reason is that the flaw is tied to how the physical chips inside the switches process data, and a code change would break the switches' existing configuration. Federal agencies are instead limited to access-control lists, which are filter rules that restrict which traffic can reach the vulnerable switches but do not fix the underlying flaw.

Deep Analysis
Root Causes

Arista EOS's tunnel verification flaw reflects a design choice in the 7020R, 7280R, and 7500R hardware ASICs (application-specific integrated circuits): the chips implement tunnel-type decapsulation in hardware logic that cannot be patched via a software update without redesigning the data-plane forwarding path.

A code fix would require the OS to reject packets the ASIC has already partially processed, which breaks the forwarding pipeline and disrupts existing tunnel configurations in production deployments.

The broader structural root cause is the KEV catalogue's assumption of software-patchable infrastructure. BOD 22-01, issued in November 2021, was designed for software applications and operating systems where vendor cooperation produces a binary: patch available, or not yet available.

The directive has no compliance pathway for a vendor who formally declines to produce a patch for a hardware-constrained reason. This is the second instance in 2026 where this gap has surfaced, following PAN-OS CVE-2026-0300 where the patch deadline arrived four days before the fix shipped.

Escalation

Stable but unresolved. No evidence of mass exploitation. The risk concentrates in federal data-centre environments running the named Arista switch series. Without a vendor patch, the exposure persists indefinitely beyond the 23 June compliance deadline.

What could happen next?
  • Precedent

    Arista's formal refusal to patch a KEV-listed flaw forces CISA to either accept an ACL-only compliance state or publish guidance for federal procurement exclusion of affected hardware series.

    Short term · Assessed
  • Risk

    Federal agencies running Arista 7020R, 7280R, or 7500R switches in segmented data-centre fabrics face a permanent residual risk without the hardware refresh required to fully remediate CVE-2026-7473.

    Medium term · Assessed
  • Consequence

    BOD 22-01 may require amendment to define a vendor non-cooperation pathway, drawing on the Arista and Exchange CVE-2026-42897 (ID:3486) cases as the documented trigger.

    Medium term · Suggested
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

SecurityWeek· 14 Jun 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.