---
id: CVE-2026-94587
title: >-
  A buffer overflow vulnerability exists in the WebTools administrative
  interface handling configuration download or file transfer operations of
  Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1
summary: >-
  A buffer overflow vulnerability exists in the WebTools administrative
  interface handling configuration download or file transfer operations of
  Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An
  authenticated user wi…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-120
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T05:17:06.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94587'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39136'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T05:05:36.678Z'
---

## Overview

A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can overflow stack buffers causing a crash of the weblinker daemon.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
