The U.S. Cybersecurity and Infrastructure Security Agency added three actively exploited flaws to its Known Exploited Vulnerabilities catalog on June 9, with the most novel entry being CVE-2026-7473, a tunnel-decapsulation weakness in Arista Extensible Operating System. Arista has confirmed in-the-wild exploitation but says it will not ship a patch.
What CVE-2026-7473 actually does
The flaw, rated 6.9 on the CVSS scale, lives in EOS switches configured as tunnel endpoints — VXLAN VTEPs, GRE tunnel interfaces, or hosts with an IP decap-group. Because EOS does not verify the tunnel protocol type before decapsulating packets that arrive at the configured decap IP, an attacker who can reach the device can smuggle unexpected encapsulated traffic past expected filters. The affected hardware spans the 7020R, 7280R/R2 and 7500R/R2 series. Comcast researchers Scott Christiansen, Lukas Peitz, Rich Compton, and Jonathan Davis were credited with the disclosure.
Arista: no patch, only ACL workarounds
In an unusual stance for a CISA KEV listing, Arista said engineering a code fix risked breaking production tunnel configurations across the install base, so the vendor will not publish one. Instead, the advisory tells operators to enforce access-control lists either on upstream devices or on the affected switches themselves, allowing legitimate tunnel sources and blocking everything else. Federal civilian agencies must apply the mitigations by June 23, 2026 under Binding Operational Directive 22-01.
Part of a triple-tap KEV update
CISA bundled the Arista entry with two other actively exploited bugs: a remote code-execution path in Cisco Catalyst SD-WAN Manager (CVE-2026-20245) and an out-of-bounds read/write in Google Chrome's V8 engine (CVE-2026-11645). The KEV additions land days after Microsoft's record June 2026 Patch Tuesday and as enterprises absorb the latest CISA BOD 26-04 risk-based vulnerability management directive.
Reporting based on coverage from The Hacker News, SecurityWeek, and Arista Security Advisory 0137.