PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14443 Brocade CVE debrief

CVE-2026-14443 is a high-severity vulnerability in Brocade SANnav that allows extension switch pre-shared keys to be written to system logs due to incomplete log sanitization during bulk IPsec policy collection. This issue affects Brocade SANnav versions before 3.0.1a. Individuals with read access to container logs or support archives can obtain these keys, potentially compromising encrypted network tunnels. The vulnerability has a CVSS score of 8.4 and is considered HIGH severity. Defenders should prioritize verifying and remediating this vulnerability, especially those with access to container logs or support archives, to prevent potential compromise of encrypted network tunnels.

Vendor
Brocade
Product
SANnav
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-25
Advisory published
2026-09-24
Advisory updated
2026-09-25

Who should care

Defenders responsible for Brocade SANnav deployments, particularly those with access to container logs or support archives, should assess exposure and prioritize remediation. This includes IT security teams, network administrators, and system operators who manage Brocade SANnav environments. Additionally, vulnerability management teams and security operations centers (SOCs) should be aware of this vulnerability and its potential impact on their networks.

Why it matters

CVE-2026-14443 is a high-severity vulnerability in Brocade SANnav that allows extension switch pre-shared keys to be written to system logs due to incomplete log sanitization. Defenders should prioritize verifying and remediating this vulnerability, especially those with access to container logs or support archives, to prevent potential compromise of encrypted network tunnels.

  • Potential compromise of encrypted network tunnels
  • Exposure of extension switch pre-shared keys
  • Increased risk of unauthorized access to sensitive data
  • Need for verification of Brocade SANnav versions and log sanitization

Technical summary

Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permits extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, potentially compromising encrypted network tunnels. The vulnerability is due to inadequate sanitization of log data, allowing sensitive information to be exposed. This issue can lead to the compromise of encrypted network tunnels if not properly addressed.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability in Brocade SANnav versions before 3.0.1a.

Recommended defensive actions

  • Verify Brocade SANnav versions and identify instances before 3.0.1a
  • Review container logs and support archives for potential exposure of pre-shared keys
  • Remediate by upgrading to Brocade SANnav version 3.0.1a or later
  • Implement additional monitoring for potential unauthorized access to encrypted network tunnels
  • Conduct a thorough review of current network configurations and security policies
  • Engage with Brocade support for guidance on remediation and potential workarounds
  • Document and track remediation efforts for audit and compliance purposes

Evidence notes

The CVE description notes incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a, allowing extension switch pre-shared keys to be written to system logs.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14443 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14443

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14443 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14443

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38998

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.