PatchSiren cyber security CVE debrief
CVE-2026-87424 Brocade CVE debrief
CVE-2026-87424 debrief based on CVE Program and NVD records. A vulnerability in Brocade ASCG's SupportLink API authentication component allows authentication bypass due to a hardcoded cryptographic key. This issue affects Brocade Active Support Connectivity Gateway versions prior to 3.5.0. The vulnerability has a high CVSS score of 8.6, indicating a critical severity level. Defenders should prioritize verifying exposure and applying patches to prevent potential authentication bypass. The CVE record and NVD detail page provide information on the vulnerability and affected versions.
- Vendor
- Brocade
- Product
- Brocade Active Support Connectivity Gateway
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Brocade ASCG deployments should assess exposure and apply patches to prevent potential authentication bypass. This includes verifying the version of Brocade ASCG and ensuring that it is not vulnerable to this authentication bypass vulnerability. Additionally, defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Why it matters
CVE-2026-87424 is a high-severity vulnerability in Brocade ASCG's SupportLink API authentication component. Defenders should prioritize verifying exposure and applying patches to prevent potential authentication bypass.
- Verify exposure of Brocade ASCG versions prior to 3.5.0 to the SupportLink API
- Apply patches to prevent authentication bypass
- Monitor for potential authentication bypass attempts
Technical summary
The SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 uses a hardcoded cryptographic key, allowing an attacker to bypass authentication across deployments. This vulnerability has a high CVSS score of 8.6, indicating a critical severity level. The CVE record and NVD detail page provide information on the vulnerability and affected versions. Defenders should prioritize verifying exposure and applying patches to prevent potential authentication bypass.
Defensive priority
Defenders should prioritize verifying exposure and applying patches for Brocade ASCG versions prior to 3.5.0.
Recommended defensive actions
- Verify Brocade ASCG version and exposure to the SupportLink API
- Apply patches for Brocade ASCG versions prior to 3.5.0
- Monitor for potential authentication bypass attempts
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability and affected versions. The CVE Program and NVD records confirm the vulnerability in Brocade ASCG's SupportLink API authentication component. The hardcoded cryptographic key allows an attacker to bypass authentication across deployments. Brocade ASCG versions prior to 3.5.0 are affected by this vulnerability. The CVE record was published on 2026-10-08T06:48:02.454Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87424 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87424
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87424 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87424
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-87424
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87424.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/38391
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.