CVE-2026-87424: Brocade Active Support Connectivity Gateway

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication across deployments due to the use of a hard coded cryptographic key.

Affected products

  • Brocade Brocade Active Support Connectivity Gateway: before 3.5.0 (fixed in 3.5.0)

Published 2026-10-08. Last modified 2026-10-08.