CVE-2026-87428High· 8.4▾ TwilightIn Brocade ASCG before 3.5.0, a local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav instances and compromise connected Brocad…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In Brocade ASCG before 3.5.0, a local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav instances and compromise connected Brocade SANnav servers or managed Brocade Fibre Channel switches.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87426Medium· 5.3An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches
CVE-2026-87425High· 7.6An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0
CVE-2026-87424High· 8.6A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication across deployments due to the use of a hard coded cryptographic key.
CVE-2026-85423High· 8.6A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0
CVE-2026-85421High· 8.7A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0
CVE-2026-85486High· 8.6Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation