CVE-2026-82370: Brocade Sannav
High severity, CVSS 8.6. EPSS: 0.6% chance of exploitation in the next 30 days.
Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a.
Affected products
- Brocade Sannav: before 3.0.1a (fixed in 3.0.1a)
Published 2026-09-24. Last modified 2026-10-01.