CVE-2026-85422: Brocade Active Support Connectivity Gateway
High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages.
Affected products
- Brocade Brocade Active Support Connectivity Gateway: before 3.5.0 (fixed in 3.5.0)
Published 2026-10-08. Last modified 2026-10-08.