CVE-2026-87684: Brocade Fabric OS

High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A stack-based buffer overflow vulnerability exists in the SNMP daemon request handling of Brocade Fabric versions before 10.0.1. When processing an incoming SNMPv3 packet, an internal statistics gathering handler copies user-supplied context name data into a fixed-size buffer without properly validating the length of the string. A remote, unauthenticated attacker (under default configuration) can exploit this vulnerability by sending a specially crafted SNMPv3 packet, leading to memory corruption, daemon crash (Denial of Service), or potential arbitrary code execution.

Affected products

  • Brocade Fabric OS: before 10.0.1 (fixed in 10.0.1)

Published 2026-10-08. Last modified 2026-10-08.