PatchSiren cyber security CVE debrief
CVE-2026-87675 Brocade CVE debrief
A high-severity OS command injection vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An administrator-initiated configuration download can cause arbitrary operating system commands to be executed on a remote local switch due to insufficient character set validation and sanitization of shell metacharacters.
- Vendor
- Brocade
- Product
- Fabric OS
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Brocade Fabric OS systems, specifically administrators and security teams, should assess exposure and prioritize verification and remediation efforts. This includes operators managing affected systems, vulnerability management teams, and security teams responsible for reviewing configuration files and ensuring system security.
Why it matters
A high-severity OS command injection vulnerability in Brocade Fabric OS requires immediate attention from defenders to assess exposure, verify affected versions, and upgrade to non-affected versions to prevent potential arbitrary operating system command execution.
- Potential for arbitrary operating system command execution on remote local switches
- Need for verification of affected versions and upgrade to non-affected versions
- Potential disruption to configuration download operations
- Need for review of configuration files for potential vulnerabilities
Technical summary
The vulnerability exists in the configuration management subsystem of Brocade Fabric OS. When performing a configuration download operation, the management daemon relays configuration parameters, user-supplied relay host strings, and filenames directly to an internal utility script without sufficient character set validation. The local utility fails to sanitize shell metacharacters before processing them in a system shell command, allowing a malicious or compromised configuration file to cause arbitrary operating system commands to be executed on a remote local switch.
Defensive priority
Defenders should prioritize verifying and upgrading to non-affected versions of Brocade Fabric OS, specifically versions 9.2.2d or later, and 10.0.0a1 or later, and assess exposure in their environment.
Recommended defensive actions
- Verify and upgrade to non-affected versions of Brocade Fabric OS
- Assess exposure in the environment
- Review configuration download operations for potential vulnerabilities
- Perform vulnerability scanning
- Implement compensating controls
- Monitor for suspicious activity
- Review asset inventory for affected systems
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and references to vendor advisories. Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 are affected. Defenders should verify and review configuration files for potential vulnerabilities. Evidence limits are based on CVE and source item details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87675 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87675
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87675 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87675
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-87675
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87675.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/39146
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.