CVE-2025-1976: Broadcom Brocade Fabric OS Code Injection Vulnerability

Medium severity, CVSS 6.7. Actively exploited: in CISA KEV since 2025-04-28. EPSS: 0.7% chance of exploitation in the next 30 days.

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.

Affected products

  • Broadcom Fabric Operating System: from 9.1.0, before 9.1.1d7 (fixed in 9.1.1d7)

Published 2025-04-24. Last modified 2026-06-17.