PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87677 Brocade CVE debrief

PatchSiren debrief for CVE-2026-87677: An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Malformed account names can cause the execution of embedded shell metacharacters, triggering command injection. This vulnerability has a medium severity and defenders of Brocade Fabric OS systems, especially administrators responsible for account management, should assess exposure and prioritize remediation to prevent potential command injection and unauthorized access.

Vendor
Brocade
Product
Fabric OS
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders of Brocade Fabric OS systems, especially administrators responsible for account management, should assess exposure and prioritize remediation to prevent potential command injection and unauthorized access. This includes reviewing and updating Brocade Fabric OS versions, restricting account deletion functionality, and monitoring account management activities for suspicious behavior. Additionally, defenders should verify and update inventory of Bro

Why it matters

CVE-2026-87677 is a medium-severity OS command injection vulnerability in Brocade Fabric OS. Defenders of Brocade Fabric OS systems, especially administrators responsible for account management, should assess exposure and prioritize remediation to prevent potential command injection and unauthorized access.

  • Potential command injection and unauthorized access.
  • Possible disruption of account management functionality.
  • Need for verification of affected versions and remediation status.
  • Potential impact on security and compliance posture.

Technical summary

An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Malformed account names can cause the execution of embedded shell metacharacters, triggering command injection. The vulnerability is caused by the lack of proper input validation in the account management subsystem, which allows attackers to inject malicious commands. The affected versions of Brocade Fabric OS are before 9.2.2d and 10.0.0 through 10.0.0a1. Defenders should review and update Brocade Fabric OS versions to 9.2.2d or later, or 10.0.0a2 or later to prevent potential command injection and unauthorized access.

Defensive priority

Medium priority for defenders of Brocade Fabric OS systems, especially administrators responsible for account management.

Recommended defensive actions

  • Review and update Brocade Fabric OS versions to 9.2.2d or later, or 10.0.0a2 or later.
  • Restrict account deletion functionality to minimize exposure.
  • Monitor account management activities for suspicious behavior.
  • Verify and update inventory of Brocade Fabric OS systems.
  • Implement additional security controls, such as network segmentation and access controls, to limit the potential impact of the vulnerability.
  • Conduct regular security audits and vulnerability assessments to identify and address potential vulnerabilities.
  • Review and update incident response plans to ensure preparedness in case of a security incident.

Evidence notes

The CVE record and source item provide details on the OS command injection vulnerability in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The vulnerability is caused by the lack of proper input validation in the account management subsystem, which allows attackers to inject malicious commands. The CVE record and source item also provide information on the affected versions and the potential impact of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87677 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87677

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87677 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87677

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-87677

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87677.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/39131

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.