CVE-2026-85486
Received Received - Intake

Brocade ASCG Remote Code Execution via Form Input

Vulnerability report for CVE-2026-85486, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Brocade ASCG before version 3.5.0 has a flaw where user input in configuration forms is processed before validation. This allows an authenticated attacker with basic access to submit crafted input that executes arbitrary code on the server, potentially taking full control of the application.

Detection Guidance

Detecting this vulnerability requires checking for outdated Brocade ASCG versions before 3.5.0. Inspect system logs for unauthorized code execution attempts or unusual configuration changes. Monitor network traffic for suspicious input patterns in configuration forms.

Impact Analysis

An attacker could exploit this to run malicious code on the server, leading to unauthorized access, data theft, or system compromise. This could disrupt services, expose sensitive information, or allow further attacks within the network.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements or HIPAA's security rules. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Immediately upgrade Brocade ASCG to version 3.5.0 or later. Disable user input processing in configuration forms until patched. Restrict access to authenticated users only and monitor for signs of compromise.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85486. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart