CVE-2026-87676
Received Received - Intake

Stack-Based Buffer Overflow in Brocade Fabric OS

Vulnerability report for CVE-2026-87676, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

A stack-based buffer overflow vulnerability exists in the security library component of Brocade Fabric OS versions before 10.0.1. When parsing uploaded X.509 PEM certificates for management display, the system improperly validates the length of the Authority Key Identifier (AKI) extension before copying string tokens into an internal memory buffer. An authenticated user with administrative privileges to import custom certificates can supply a certificate containing an intentionally oversized AKI extension. When the system processes or renders the certificate attributes, this can trigger a stack memory corruption leading to a denial-of-service (DoS) condition by crashing the management daemon.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in Brocade Fabric OS versions before 10.0.1. When processing X.509 PEM certificates, the system fails to validate the length of the Authority Key Identifier (AKI) extension. An authenticated admin can upload a malicious certificate with an oversized AKI, causing memory corruption when the system renders the certificate. This leads to a denial-of-service by crashing the management daemon.

Detection Guidance

This vulnerability can be detected by checking the version of Brocade Fabric OS running on your system. If the version is before 10.0.1, the system is vulnerable. No specific commands are provided in the context to detect the vulnerability directly.

Impact Analysis

If you use Brocade Fabric OS versions before 10.0.1, an attacker with admin access could crash the management interface by uploading a specially crafted certificate. This disrupts system management and monitoring, potentially causing downtime or loss of visibility into the fabric.

Compliance Impact

This vulnerability could impact compliance by causing unplanned downtime or loss of system management capabilities. For GDPR, it may affect availability of processing systems. For HIPAA, it could disrupt access to critical infrastructure monitoring. However, the direct compliance impact depends on specific deployment contexts.

Mitigation Strategies

Immediately upgrade Brocade Fabric OS to version 10.0.1 or later to address the stack-based buffer overflow vulnerability. Ensure only trusted certificates are imported and restrict administrative access to certificate management functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87676. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart