CVE-2026-85490High· 7.7▾ TwilightWhen Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthentica…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthenticated remote attacker capable of sending or intercepting ingested archive files can leverage this flaw to write arbitrary files to restricted locations on the underlying host, potentially leading to remote code execution.
active_support_connectivity_gateway < 3.5.0Security update provided in Brocade ASCG 3.5.0
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85487High· 8.6A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0
CVE-2026-85423High· 8.6A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0
CVE-2026-85486High· 8.6Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation
CVE-2026-85421High· 8.7A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0
CVE-2026-85488High· 7.0Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer
CVE-2026-85422High· 8.4A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols