PatchSiren cyber security CVE debrief
CVE-2026-85487 Brocade CVE debrief
A path traversal vulnerability exists in Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint, bypassing path restrictions to arbitrary file read, file write, or file deletion operations. This vulnerability allows for potential unauthorized data access or modification, emphasizing the need for defenders to assess exposure and prioritize verification and updates. The CVE record and source item provide details on the vulnerability, and defenders should focus on verifying exposure and assessing potential impact.
- Vendor
- Brocade
- Product
- Brocade Active Support Connectivity Gateway
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems using Brocade ASCG versions before 3.5.0 should assess exposure and prioritize verification and potential updates. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review the vulnerability's impact on their environments and plan accordingly.
Why it matters
CVE-2026-85487 is a path traversal vulnerability in Brocade ASCG that allows unauthenticated attackers to perform arbitrary file operations. Defenders should prioritize verifying exposure, assessing potential impact, and updating to version 3.5.0 or later if possible.
- Potential for arbitrary file operations
- Risk of unauthorized data access or modification
- Need for network traffic monitoring
- Priority for version updates or patches
Technical summary
The path traversal vulnerability in Brocade ASCG allows an unauthenticated attacker on the local network to send a manipulated API request, potentially leading to arbitrary file read, write, or deletion operations. This vulnerability is grounded in the CVE record and source item details, emphasizing the need for defenders to prioritize verifying exposure and assessing potential impact without unsupported root-cause or exploit claims. Affected product context and defensive impact should be considered in vulnerability management.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems using Brocade ASCG versions before 3.5.0.
Recommended defensive actions
- Verify Brocade ASCG version and assess exposure
- Implement network restrictions to limit access to the HTTP service
- Monitor for suspicious API requests
- Update to version 3.5.0 or later if possible
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the path traversal vulnerability in Brocade ASCG. The vendor, Brocade, is the canonical source for affected products. Evidence is limited to public CVE details and source item information. Defenders should verify the existence of affected products in their environments and review official advisories for validation of affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85487 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85487
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85487 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85487
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-85487
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/85xxx/CVE-2026-85487.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/38383
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.