CVE-2026-87426
Received Received - Intake

Information Disclosure in Brocade ASCG

Vulnerability report for CVE-2026-87426, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker on the network to query internal management endpoints on vulnerable Brocade ASCG versions before 3.5.0. By doing so, the attacker can gather sensitive configuration details and operational state of Brocade Fabric OS (FOS) switches managed by the ASCG. This leads to unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes.

Detection Guidance

To detect this vulnerability, scan your network for Brocade ASCG instances running versions before 3.5.0. Check for exposed management endpoints by querying internal management interfaces. Use network scanning tools like nmap to identify Brocade devices and verify their firmware versions.

Impact Analysis

An attacker could use this vulnerability to map out your SAN fabric infrastructure, identify switch connections, and understand your storage network topology. This information could be used to plan further attacks, such as targeting specific switches or disrupting storage operations.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive network configuration details and switch connectivity attributes. Unauthorized disclosure of SAN fabric management topology may violate data protection requirements under GDPR for safeguarding personal data and under HIPAA for protecting health information.

Mitigation Strategies

Immediately upgrade Brocade ASCG to version 3.5.0 or later. Ensure management endpoints are not exposed to untrusted networks. Apply network segmentation to restrict access to these endpoints. Review and audit all Brocade Fabric OS switch configurations for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87426. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart