๐Ÿ” CVE Alert

CVE-2026-86107

MEDIUM 5.9

Security Advisory 0180

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful exploit can cause the affected process to terminate and restart, leading to a temporary disruption of traffic. Hosts on the internet that are unauthenticated and unable to form an overlay peer relationship can not trigger the vulnerable logic.

CWE CWE-787
Vendor arista networks
Product velocloud
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for arista networks velocloud

Be the first to know when new medium vulnerabilities affecting arista networks velocloud are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Arista Networks / VeloCloud
1.0.0.0 < 5.2.0.0 5.2.0.0 < 5.2.7.0 6.1.0.0 < 6.1.5.0 6.4.0.0 < 6.4.2.0
Arista Networks / VeloCloud Gateway
1.0.0.0 < 5.2.0.0 5.2.0.0 < 5.2.7.0 6.1.0.0 < 6.1.5.0 6.4.0.0 < 6.4.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
arista.com: https://www.arista.com/en/support/advisories-notices/security-advisory/24736-security-advisory-0180