CVE-2026-94585: Brocade Fabric OS

High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the device management interface.

Affected products

  • Brocade Fabric OS: before 9.2.2d (fixed in 9.2.2d)

Published 2026-10-08. Last modified 2026-10-08.