CVE-2026-73446

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.

  • Published Sep 16, 2026
  • CVSS 7.0 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-73446 at the National Vulnerability Database