CVE-2026-87426: Brocade Active Support Connectivity Gateway

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes.

Affected products

  • Brocade Brocade Active Support Connectivity Gateway: before 3.5.0 (fixed in 3.5.0)

Published 2026-10-08. Last modified 2026-10-08.