CVE-2026-87660: Brocade Fabric OS

High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper file permission and missing authorization vulnerability exists in the diagnostic kernel module subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An unprivileged local user can invoke privileged hardware tests, force system error conditions, reset hardware blades, or disrupt storage fabric operations.

Affected products

  • Brocade Fabric OS: before 9.2.2d (fixed in 9.2.2d); from 10.0.0, up to and including 10.0.0a1

Published 2026-10-08. Last modified 2026-10-08.