CVE-2026-85487: Brocade Active Support Connectivity Gateway

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restrictions to arbitrary file read, file write, or file deletion operations.

Affected products

  • Brocade Brocade Active Support Connectivity Gateway: before 3.5.0 (fixed in 3.5.0)

Published 2026-10-08. Last modified 2026-10-08.