Arista published its batch of security advisories on September 9, turning an advance warning into an immediate customer maintenance task. The release includes critical vulnerabilities affecting EOS and VeloCloud. Cisco’s September 4 security commentary describes the broader problem: vulnerability discovery is accelerating beyond customers’ ability to remediate it.
For Cisco Systems, Inc. (NASDAQ:CSCO) and Arista Networks, Inc. (NYSE:ANET), that creates an investment question beyond port speeds. Can suppliers keep expanding AI networks without letting the cost and disruption of securing them erode customer confidence?

Ken Wolter / Shutterstock.com
Critical findings create an immediate task
Cisco says it scanned 1.8 billion lines of code across 25 languages in eight weeks using frontier models. Its September 2 advisories already include critical issues involving IOS XR and Nexus 9000 switches using Silicon One. Customers have been directed to fixed software.
That is a potential advantage if earlier detection prevents expensive incidents. Cisco’s breadth across networking, security and support could also help customers coordinate their response. Yet finding defects creates engineering and service obligations before it creates incremental revenue. Entitlement to free security upgrades makes it especially risky to treat every patch as a paid refresh.
Arista’s updated summary lists critical EOS gNPSI and P4Runtime vulnerabilities with CVSS v3.1 scores of 10, alongside other findings. Customers must assess the conditions and remediation for their own environments. Severity scores alone do not establish exploitation or an earnings loss. Its May statement also says AI-assisted testing caught complex flaws before software release, evidence that better detection can prevent some customer exposure.
For Arista Networks, Inc., consolidating updates into maintenance windows could strengthen its appeal to customers running demanding networks. The bear case is that testing and deployment consume resources that customers otherwise devote to expansion. Cisco Systems, Inc. faces the same friction, with additional complexity from its wider product portfolio.
Ownership offers context
In Insider Monkey’s tracked worksheet sample, Cisco appeared in 101 portfolios in Q2 2026 versus 97 in Q1; Arista rose to 91 from 85. The sample covered 1,006 and 1,022 managers, respectively. At June 30, Ken Fisher’s firm reported 33,412,725 Cisco shares, while Steve Cohen’s Point72 held 5,139,737 Arista shares. These historical snapshots do not reveal managers’ reactions to September disclosures.
The August 14 settlement figures put short interest at 1.50% of Cisco’s float and 1.05% of Arista’s. Neither figure measures the operational burden of patching.
The useful test is customer execution: timely fixes, manageable disruption and continued deployments. AI-assisted discovery could make both networks safer over time. Shareholders still need that improvement to arrive without a disproportionate support bill.
READ NEXT: The Trillion-Dollar AI Capex Gap: Why Too Much Hardware Could Be Nvidia’s Trap and Microsoft’s Opportunity and Redditors Are Skeptical of SpaceX’s Orbital Data Centers. Are They Right?