CVE-2026-87679: high-severity vulnerability in Brocade Fabric OS
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5
exploitation probability
—
observed exploitation
nono source reports it
When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boundary checks on the maximum allowable number of elements. An authenticated administrator can exploit this vulnerability via crafted REST API requests containing an excessive number of list delimiters, causing heap corruption that can result in service crash or arbitrary code execution.
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Brocade · Fabric OSRelated CVEs — Brocade Fabric OS
In the same product, most dangerous first.
CVE-2025-1976HIGHCode injection exposure in Fabric OS 9.1.0 through 9.1.1d6EPSS 0.7%KEVCVE-2023-3454HIGHCVE-2023-3454EPSS 1.2%CVE-2024-10403MEDIUMSFTP/FTP password could be captured in plain text in Supportsave generated from SANnavEPSS 0.7%CVE-2025-58382HIGHPrivilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2aEPSS 0.6%CVE-2023-31927MEDIUMAn information disclosure in the web interface of Brocade Fabric OSEPSS 0.6%CVE-2024-7517HIGHPrivileged escalation via crafted use of portcfg commandEPSS 0.6%