CVE-2026-85421High· 8.7▾ TwilightA critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0. The HTTPS service fails to properly enforce authentication or access control checks on incoming requests. An unauthenticated attacker with netwo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0. The HTTPS service fails to properly enforce authentication or access control checks on incoming requests. An unauthenticated attacker with network access can issue control commands, alter cluster states, and modify system configurations, leading to a complete compromise of the streaming service control plane.
active_support_connectivity_gateway < 3.5.0Security update provided in Brocade ASCG 3.5.0
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85423High· 8.6A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0
CVE-2026-85489High· 8.7An authentication flaw exists in the Brocade ASCG administrative management service component
CVE-2026-85486High· 8.6Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation
CVE-2026-85488High· 7.0Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer
CVE-2026-85487High· 8.6A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0
CVE-2026-85422High· 8.4A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols