PatchSiren cyber security CVE debrief
CVE-2026-87426 Brocade CVE debrief
CVE-2026-87426 debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T06:54:22.995Z and has not been modified since then. This vulnerability affects Brocade Active Support Connectivity Gateway (ASCG) versions before 3.5.0, allowing unauthenticated network-based attackers to query specific internal management endpoints and enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes. Defenders responsible for Brocade ASCG deployments should assess exposure and verify the security of their SAN.
- Vendor
- Brocade
- Product
- Brocade Active Support Connectivity Gateway
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Brocade Active Support Connectivity Gateway (ASCG) deployments, particularly those using versions before 3.5.0, should assess exposure and verify the security of their SAN fabric management topology.
Why it matters
CVE-2026-87426 allows unauthenticated network-based attackers to query specific internal management endpoints on vulnerable Brocade ASCG versions, resulting in unauthorized disclosure of SAN fabric management topology and switch connectivity attributes. Defenders should prioritize verifying exposure, assessing security, and implementing compensating controls.
- Verify exposure of Brocade ASCG versions before 3.5.0.
- Assess the security of SAN fabric management topology and switch connectivity attributes.
- Implement compensating controls to limit the attack surface.
- Monitor for potential exploitation attempts.
Technical summary
An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches, resulting in unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes. This vulnerability affects Brocade Active Support Connectivity Gateway (ASCG) deployments, particularly those using versions before 3.5.0. Defenders should prioritize verifying exposure of Brocade ASCG versions before 3.5.0 and assessing the security of their SAN fabric management topology.
Defensive priority
Defenders should prioritize verifying exposure of Brocade Active Support Connectivity Gateway (ASCG) versions before 3.5.0 and assessing the security of their SAN fabric management topology.
Recommended defensive actions
- Verify the version of Brocade ASCG in use and check if it is vulnerable (less than 3.5.0).
- Assess the security of the SAN fabric management topology and switch connectivity attributes.
- Implement compensating controls to limit the attack surface, such as restricting access to internal management endpoints.
- Monitor for potential exploitation attempts and implement detection and response measures.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and source item provide details on an unauthenticated network-based attacker's ability to query specific internal management endpoints on Brocade ASCG versions before 3.5.0, resulting in unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87426 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87426
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87426 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87426
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-87426
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87426.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/38393
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.