CVE-2026-87671: High severity Brocade Fabric OS vulnerability

Published Oct 8, 2026
·
Updated

An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.

Affected Software

1 affected component
Brocade Fabric OS<10.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Brocade Fabric OS to a version that resolves this vulnerability.

    Fixed in 10.0.1

Event History

Oct 8, 2026
CVE Published
via MITRE·02:22 AM
Data Sourced
via MITRE·02:22 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Brocade Fabric OS versions before 10.0.1 are affected where the web management daemon and its HTTP endpoints are reachable by an attacker. The issue affects the management plane rather than data confidentiality or integrity.

2

Does exploitation require authentication or user interaction?

No. An unauthenticated remote attacker can trigger the issue with a single crafted HTTP request, and no user interaction is required.

3

What is the expected impact of a successful attack?

Successful exploitation crashes the web management process, causing a denial of service and potentially temporary disruption of management-plane access. The provided information does not indicate an impact on confidentiality or integrity.

4

What input is used to trigger the vulnerability?

The attack uses extreme numerical values in URL query-string parameters handled by unauthenticated HTTP endpoints. These values cause an out-of-bounds memory read through invalid array indexing or missing numerical range validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203