Skip to content
Arista NetworksCVE-2026-86107

Arista Networks VeloCloud: out-of-bounds write

High8.2CVE-2026-86107 · Published Sep 16, 2026

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful exploit can cause the affected process to terminate and restart, leading to a temporary disruption of traffic. Hosts on the internet that are unauthenticated and unable to form an overlay peer relationship can not trigger the vulnerable logic.

Arista Networks advisory

Affected versions

PackageAffectedFixed in
VeloCloud
Product
>= 1.0.0.0, < 5.2.0.05.2.0.0
>= 5.2.0.0, < 5.2.7.05.2.7.0
>= 6.1.0.0, < 6.1.5.06.1.5.0
>= 6.4.0.0, < 6.4.2.06.4.2.0
VeloCloud Gateway
Product
>= 1.0.0.0, < 5.2.0.05.2.0.0
>= 5.2.0.0, < 5.2.7.05.2.7.0
>= 6.1.0.0, < 6.1.5.06.1.5.0
>= 6.4.0.0, < 6.4.2.06.4.2.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-787

More Arista Networks advisories

All Arista Networks
Advisory
Arista Networks EOS: remote code execution
Critical9.2Sep 16
Arista Networks EOS: secrets in logs
Medium6.0Sep 16
Arista Networks EOS: out-of-bounds read
High7.1Sep 16
Arista Networks EOS: secrets in logs
Low2.1Sep 16
Arista Networks EOS: denial of service
Medium5.3Sep 16
Arista Networks VeloCloud Edge: missing authentication
High8.7Sep 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.