CVE-2026-87661
Received Received - Intake

Brocade Fabric OS Configuration Corruption DoS

Vulnerability report for CVE-2026-87661, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 directly accepts Apache configuration file data during service setup or re-initialization. An attacker capable of corrupting the configuration structure will prevent the web management service from starting or recovering during service bring-up, leading to a persistent Denial of Service (DoS) of the administrative web interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Brocade Fabric OS 0
Brocade Fabric OS 10.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-93 The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. It allows an attacker to corrupt Apache configuration file data during service setup or re-initialization. This corruption can prevent the web management service from starting or recovering, causing a persistent Denial of Service (DoS) for the administrative web interface.

Detection Guidance

This vulnerability affects Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Detection involves checking the installed version of Brocade Fabric OS. Use commands like 'version' or 'show version' on the Brocade device to verify the OS version. If the version is below 9.2.2d or between 10.0.0 and 10.0.0a1, the system is vulnerable.

Impact Analysis

An attacker exploiting this vulnerability could cause the administrative web interface to become unavailable. This results in a persistent Denial of Service (DoS), meaning you may lose access to critical management functions for the Brocade Fabric OS until the issue is resolved.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by disrupting the availability of administrative web interfaces used to manage data access and security controls. Persistent DoS of these interfaces may hinder timely incident response and audit logging, which are critical for regulatory compliance.

Mitigation Strategies

Upgrade Brocade Fabric OS to version 9.2.2d or later, or 10.0.0a2 or later to address the configuration file corruption issue. Ensure the web management service is restarted after the upgrade to verify proper functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87661. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart