CVE-2026-87673: Brocade Fabric OS

High severity, CVSS 7.0. EPSS: 0.9% chance of exploitation in the next 30 days.

An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The binary fails to sanitize user-supplied input options when invoking underlying system commands through a shell interpreter. A privileged user with maintenance account access can exploit this issue by supplying crafted parameters, which results in arbitrary OS command execution with root privileges.

Affected products

  • Brocade Fabric OS: before 9.2.2d (fixed in 9.2.2d); from 10.0.0, up to and including 10.0.0a1

Published 2026-10-08. Last modified 2026-10-09.