CVE-2026-82368: Brocade Sannav

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user.

Affected products

  • Brocade Sannav: before 3.0.1a (fixed in 3.0.1a)

Published 2026-09-23. Last modified 2026-10-01.