---
id: CVE-2026-87426
title: >-
  An unauthenticated network-based attacker can query specific internal
  management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the
  configuration details and state of managed Brocade Fabric OS (FOS) switches
summary: >-
  An unauthenticated network-based attacker can query specific internal
  management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the
  configuration details and state of managed Brocade Fabric OS (FOS) switches.
  This results i…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-200
vendor: Brocade
product: Brocade Active Support Connectivity Gateway
affected:
  - active_support_connectivity_gateway < 3.5.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T07:16:33.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87426'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/38393'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T09:24:17.685Z'
---

## Overview

An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
