CVE-2026-87428: Brocade Active Support Connectivity Gateway

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

In Brocade ASCG before 3.5.0, a  local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav instances and compromise connected Brocade SANnav servers or managed Brocade Fibre Channel switches.

Affected products

  • Brocade Brocade Active Support Connectivity Gateway: before 3.5.0 (fixed in 3.5.0)

Published 2026-10-08. Last modified 2026-10-08.