---
id: CVE-2026-87671
title: >-
  An out-of-bounds memory read vulnerability exists in the web management daemon
  of Brocade Fabric OS versions before 10.0.1
summary: >-
  An out-of-bounds memory read vulnerability exists in the web management daemon
  of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints
  process specific URL query parameters without validating array index
  boundaries or…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 10.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T03:16:36.650'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87671'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39141'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T03:03:35.549Z'
---

## Overview

An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
