CVE-2026-94586: high-severity vulnerability in Brocade Fabric OS
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5
exploitation probability
—
observed exploitation
nono source reports it
A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can supply malicious parameter strings to execute arbitrary shell commands on the switch with root privileges
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Brocade · Fabric OSRelated CVEs — Brocade Fabric OS
In the same product, most dangerous first.
CVE-2025-1976HIGHCode injection exposure in Fabric OS 9.1.0 through 9.1.1d6EPSS 0.7%KEVCVE-2023-3454HIGHCVE-2023-3454EPSS 1.2%CVE-2024-10403MEDIUMSFTP/FTP password could be captured in plain text in Supportsave generated from SANnavEPSS 0.7%CVE-2025-58382HIGHPrivilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2aEPSS 0.6%CVE-2023-31927MEDIUMAn information disclosure in the web interface of Brocade Fabric OSEPSS 0.6%CVE-2024-7517HIGHPrivileged escalation via crafted use of portcfg commandEPSS 0.6%