CVE-2026-85490: high-severity vulnerability in Brocade Active Support Connectivity Gateway
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7
exploitation probability
—
observed exploitation
nono source reports it
When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthenticated remote attacker capable of sending or intercepting ingested archive files can leverage this flaw to write arbitrary files to restricted locations on the underlying host, potentially leading to remote code execution.
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Brocade · Brocade Active Support Connectivity GatewayRelated CVEs — Brocade Active Support Connectivity Gateway
In the same product, most dangerous first.