Arista EOS End of Life: 4.31.x Support Ends October 13, 2026 — What 4.30 to 4.36 Owners Should Know
Arista EOS 4.31.x reaches its End of Support Date on October 13, 2026, 36 months after its initial release on October 13, 2023. Both dates are from the release support matrix on Arista's EOS Life Cycle Policy page, which already lists the train in its Support Only phase: TAC support continues, but a bug fix means moving to a newer train. After the End of Support Date, 4.31.x joins 4.30.x and the older trains that Arista says have reached End of Support. The train's live status and EOL Risk Score are on its page.
Arista's EOS life cycle policy, in plain words
Arista states the rule in one sentence on the policy page: "Arista will support each major EOS software release for up to 36 months from the date of initial posting for a particular train." A train is a major release line such as 4.31.x; the individual builds inside it carry a letter that tells you which phase the train is in. In Arista's words: “Each EOS software release is identified with either the letter "F" indicating that the release contains new Functionality or "M", denoting that the release is in the Maintenance phase. An M release only receives incremental fixes and no new functionality is added.” The policy page names no other kind of train: there are F builds, M builds and the three phases below.
| Phase in Arista's policy | What Arista says it includes | What it means for a switch on that train |
|---|---|---|
| New Feature Phase | Releases “identified with the letter "F" indicating that the release contains new feature/functionality”; “TAC support available” | New features arrive in F builds. The train is young; Arista's diagram, which it marks as a generic example, shows the New Feature and Maintenance phases together lasting 30 months |
| Maintenance Phase | Releases “identified with the letter "M" for maintenance phase”; “An M release only receives incremental fixes and no new functionality is added”; “TAC support available” | Bug fixes keep coming as M builds of the same train. Most of a train's life is spent here |
| Support Only Phase | “Ongoing TAC support”; “Software upgrade required for bug fixes” | You can still open a case, but a bug found now is fixed in a later train. The same generic diagram shows this phase as the final 6 months of the 36. 4.31.x is here until October 13, 2026 |
| End of Support | The state of the trains below the line in Arista's table: "Arista EOS 4.30 and earlier releases have reached End of Support." | The 36 months are over. Arista's policy page lists no support for the train; migration help is a sales conversation |
Arista's table prints two dates per train, the Initial Release Date and the End of Support Date, which it labels "+36 months from initial release". It does not print the day a train leaves Maintenance for Support Only, so the Arista EOS page and this guide serve the release and end-of-support dates only; the phase column in Arista's table is a snapshot, and Arista notes that "Future dates are for general planning purposes and are subject to change".
What changes for 4.31.x on October 13, 2026
Less than you might expect on the day, and more over the months after it. Arista's table already shows 4.31.x in the Support Only phase, so the train has not had new M builds for some time; a bug found in 4.31.x today is already answered with "upgrade". What October 13, 2026 marks is the end of the 36 months of support Arista promises for the train, including the TAC support the Support Only phase still carries. From then on, 4.31.x belongs with the releases Arista's page describes as having "reached End of Support", the line it draws today under 4.30.x (End of Support April 14, 2026). A switch that keeps running 4.31.x keeps forwarding packets; what it loses is a vendor that will look at its software.
Two things the date does not do. It does not change hardware support, which Arista tracks separately on its end-of-sale notices, and it does not change the exploited-vulnerability picture, because CVE-2026-7473 is not fixed in any train.
Every EOS train in Arista's table, and where it stands
| Train | Initial release | End of Support (EOL) | Status today |
|---|---|---|---|
| EOS 4.36.x | April 8, 2026 | April 8, 2029 | Supported |
| EOS 4.35.x | October 6, 2025 | October 6, 2028 | Supported |
| EOS 4.34.x | April 25, 2025 | April 25, 2028 | Supported |
| EOS 4.33.x | October 10, 2024 | October 10, 2027 | Approaching |
| EOS 4.32.x | April 9, 2024 | April 9, 2027 | Approaching |
| EOS 4.31.x | October 13, 2023 | October 13, 2026 | Approaching |
| EOS 4.30.x | April 14, 2023 | April 14, 2026 | EOL |
| EOS 4.29.x | October 31, 2022 | October 31, 2025 | EOL |
| EOS 4.28.x | April 18, 2022 | April 18, 2025 | EOL |
| EOS 4.27.x | September 27, 2021 | September 27, 2024 | EOL |
| EOS 4.26.x | April 15, 2021 | April 15, 2024 | EOL |
Every date is Arista's, copied from the Initial Release Date and End of Support Date columns of the matrix on the policy page; the status column is computed from those dates at every build of this site. Arista's phase column, as the table currently stands, has 4.36.x in the New Feature Phase, 4.32.x to 4.35.x in the Maintenance Phase, 4.31.x in Support Only and 4.30.x and older at End of Support. Trains older than 4.26.x are not in Arista's table.
Hardware exceptions. Arista's table carries a Platform Specific Exceptions column. For 4.33.x it keeps the 7280R/7280R2, 7500R/7500R2 and 7020R series in the Maintenance Phase beyond the train's general date, and for 4.28.x it did the same for the 7050X/7050X2, 7300X and 7010T series; Arista's footnote adds that the Support Only phase is "extended till the end of life of respective hardware" as listed on its end-of-sale page. The dates in this table are for each train in general; the per-platform exception dates are on the Arista EOS page.
The pattern is regular: Arista has posted a new train roughly every six months, one each spring and one each autumn, and every train's End of Support Date in the table is exactly 36 months after its initial release. A switch that moves train every two years never spends time in Support Only; one that moves every three arrives there every time.
The exploited flaw an upgrade does not fix
CISA's Known Exploited Vulnerabilities catalog files Arista EOS under the vendor "Arista" and the product "Extensible Operating System", and holds one entry for it. CISA's fields, quoted as the catalog prints them:
| CISA field | Catalog value |
|---|---|
| cveID | CVE-2026-7473 |
| vulnerabilityName | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability |
| dateAdded | June 9, 2026 |
| dueDate | June 23, 2026 (the federal remediation deadline) |
| shortDescription | "Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP." |
| requiredAction | "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable." |
| knownRansomwareCampaignUse | Unknown |
| cwes | CWE-1023 |
Arista's own account is Security Advisory 0137. It says "This issue has been reported as being exploited in the wild", and its affected-software list is every train: "All releases in the 4.36.x train" down to "All releases in the 4.30.x train", then "All releases in trains older than 4.30.x" and "All releases in trains newer than 4.36.x". The affected platforms are the 7020R Series, 7280R/R2 Series and 7500R/R2 Series, with "Limited exposure (IP-in-IPv6 and GUEv6)" on the 7280R3, 7500R3 and 7800R3 Series; the advisory's long list of unaffected products includes the 7050X and 7060X data-centre families, CloudEOS and the VeloCloud line. A device is exposed only when it is "configured as a tunnel endpoint with a decapsulation IP", such as a VXLAN VTEP, a GRE tunnel endpoint or an ip decap-group: it then "will also incorrectly accept and decapsulate other tunnel protocols destined to the same IP address".
Under Resolution the advisory says: "No software upgrade path is planned to address this issue due to the risk of breaking existing configuration on deployments. The recommended resolution of this issue is to follow the appropriate mitigation instructions detailed above." Under Hotfix: "No hotfix is available for these issues." The mitigations are access lists, applied either on upstream devices or on the decapsulating switch itself, that permit only the tunnel protocol a decapsulation address is meant to receive and deny the rest. That is why the end-of-support question and the exploited-flaw question are separate for Arista EOS: moving from 4.31.x to a supported train is right for every other reason, and does nothing for this one.
The two other Arista entries in CISA's catalog, CVE-2026-16812 and CVE-2026-93952, are in VeloCloud Orchestrator, a different product with its own end-of-support story. Arista EOS is on our EOS Edge Device List because the 7280R and 7500R routing families sit at peering and internet edges, which is exactly where CVE-2026-7473 lands.
What to do
- On 4.31.x: pick a train whose End of Support Date is years out. 4.34.x (End of Support April 25, 2028) and 4.35.x (October 6, 2028) are in Arista's Maintenance Phase; 4.36.x (April 8, 2029) is still in its New Feature Phase, so its M builds are ahead of it. 4.32.x buys only until April 9, 2027.
- Check the platform before the train. Arista's release notes list which hardware each train supports, and the table's platform exceptions show that some older R-series platforms are deliberately kept on older trains. Confirm the target train for your exact model and the upgrade path Arista documents for it.
- On 4.30.x or older: Arista's page already counts you among the releases that have reached End of Support. There is no Support Only phase left to lean on; the move is overdue.
- On the 7020R, 7280R/R2 or 7500R/R2 series, any train: run the three checks in Advisory 0137 (the VXLAN interface, tunnel interface and ip decap-group show commands). If any shows a decapsulation address, apply the access lists the advisory gives, and permit the management and routing protocols that address also serves before the deny line.
- Watch the dates, not the phase labels. Arista's table prints the End of Support Date for every train and nothing for the Maintenance to Support Only hand-off, and it says future dates are for planning purposes. The Arista EOS page re-reads the table and shows each train's live status.
Frequently Asked Questions
When is Arista EOS 4.31 end of life?
Arista's EOS Life Cycle Policy table gives Arista EOS 4.31.x an End of Support Date of October 13, 2026, 36 months after its initial release on October 13, 2023. Arista's table already lists the train in the Support Only phase: TAC support continues until the End of Support Date, but a software upgrade is required for bug fixes.
What does Arista's Support Only phase mean?
Arista describes the Support Only phase with two lines: ongoing TAC support, and software upgrade required for bug fixes. A switch on a Support Only train can still open a case with Arista's TAC, but a fix for a bug found in that train is delivered in a later train, not as a new 4.31 build.
Which Arista EOS trains are still within their support window?
Arista's table lists 4.32.x through 4.36.x inside their 36-month windows: 4.32.x reaches End of Support on April 9, 2027 and 4.36.x, the newest train in the table, on April 8, 2029. Below the table Arista states that Arista EOS 4.30 and earlier releases have reached End of Support.
Does upgrading EOS fix CVE-2026-7473?
No. Arista's Security Advisory 0137 lists every EOS train, including trains newer than 4.36.x, as affected, and says no software upgrade path is planned to address this issue. CISA added CVE-2026-7473 to its Known Exploited Vulnerabilities catalog on June 9, 2026. The mitigation is configuration: access lists that admit only the tunnel protocol a decapsulation address is meant to receive.
Related
- Arista EOS — every train, live status and EOL Risk Score
- The EOS Edge Device List — end-of-support status for every edge platform we track
- Arista VeloCloud end of life
- Check Point, F5 and Arista VeloCloud: exploited flaws and end of support
- Cisco IOS XR 7.8 end of life