PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87424 Brocade CVE debrief

CVE-2026-87424 debrief based on CVE Program and NVD records. A vulnerability in Brocade ASCG's SupportLink API authentication component allows authentication bypass due to a hardcoded cryptographic key. This issue affects Brocade Active Support Connectivity Gateway versions prior to 3.5.0. The vulnerability has a high CVSS score of 8.6, indicating a critical severity level. Defenders should prioritize verifying exposure and applying patches to prevent potential authentication bypass. The CVE record and NVD detail page provide information on the vulnerability and affected versions.

Vendor
Brocade
Product
Brocade Active Support Connectivity Gateway
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Brocade ASCG deployments should assess exposure and apply patches to prevent potential authentication bypass. This includes verifying the version of Brocade ASCG and ensuring that it is not vulnerable to this authentication bypass vulnerability. Additionally, defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Why it matters

CVE-2026-87424 is a high-severity vulnerability in Brocade ASCG's SupportLink API authentication component. Defenders should prioritize verifying exposure and applying patches to prevent potential authentication bypass.

  • Verify exposure of Brocade ASCG versions prior to 3.5.0 to the SupportLink API
  • Apply patches to prevent authentication bypass
  • Monitor for potential authentication bypass attempts

Technical summary

The SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 uses a hardcoded cryptographic key, allowing an attacker to bypass authentication across deployments. This vulnerability has a high CVSS score of 8.6, indicating a critical severity level. The CVE record and NVD detail page provide information on the vulnerability and affected versions. Defenders should prioritize verifying exposure and applying patches to prevent potential authentication bypass.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for Brocade ASCG versions prior to 3.5.0.

Recommended defensive actions

  • Verify Brocade ASCG version and exposure to the SupportLink API
  • Apply patches for Brocade ASCG versions prior to 3.5.0
  • Monitor for potential authentication bypass attempts

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability and affected versions. The CVE Program and NVD records confirm the vulnerability in Brocade ASCG's SupportLink API authentication component. The hardcoded cryptographic key allows an attacker to bypass authentication across deployments. Brocade ASCG versions prior to 3.5.0 are affected by this vulnerability. The CVE record was published on 2026-10-08T06:48:02.454Z and has not been modified since then.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87424 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87424

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87424 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87424

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-87424

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87424.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/38391

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.