VYPR
Published Oct 8, 2026· Updated Oct 9, 2026· 1 source

Broadcom Fabric OS: 19 Vulnerabilities Including Command Injection and Auth Bypass Disclosed Together

Key findings • Nineteen vulnerabilities disclosed simultaneously for Broadcom Fabric OS, affecting versions prior to 10.0.1. • Multiple high-severity flaws include OS command injection, privi…

Key findings

  • Nineteen vulnerabilities disclosed simultaneously for Broadcom Fabric OS, affecting versions prior to 10.0.1.
  • Multiple high-severity flaws include OS command injection, privilege escalation, and authorization bypass.
  • Vulnerabilities impact various components, including REST API, web interfaces, CLI, and inter-switch communication.
  • Patches are available in Fabric OS versions 9.2.2d, 10.0.0a1, and 10.0.1, with 10.0.1 addressing all disclosed issues.
  • Urgent upgrades are recommended to prevent unauthorized access and command execution.
  • The disclosure occurred on October 8, 2026, within a four-hour window.

On October 8, 2026, a coordinated disclosure event revealed 19 vulnerabilities affecting Broadcom's Brocade Fabric OS, with all flaws impacting versions prior to 10.0.1. The batch of vulnerabilities, disclosed within a four-hour window, spans a range of severity levels, from low to high, with a significant number of high-severity command injection and authorization bypass flaws. These vulnerabilities expose the operating system to risks including arbitrary command execution, privilege escalation, and authentication bypass.

Several vulnerabilities center on OS command injection, a recurring theme across different components of Fabric OS. CVE-2026-94581 and CVE-2026-87680 highlight command injection flaws in the REST API management interface, allowing authenticated attackers to execute arbitrary system commands. Similarly, CVE-2026-94579 points to an OS command injection vulnerability in PAM session cleanup routines during SSH termination, while CVE-2026-87673 affects maintenance CLI diagnostic utilities. CVE-2026-87666 details command injection in the time and zone management subsystem, and CVE-2026-87682 encompasses multiple command injection vulnerabilities in management interfaces and session processing.

Beyond command injection, privilege escalation and authentication bypass are also significant concerns. CVE-2026-94577 describes a privilege escalation vulnerability in the internal CLI authorization handling, allowing authenticated users to bypass Role-Based Access Control. CVE-2026-87659 presents a critical authorization bypass in the Management Server, enabling a compromised switch to transmit crafted Fibre Channel management requests to bypass administrative authentication. CVE-2026-87686 details an authentication and access control bypass in the web server management interface, which incorrectly uses the client-supplied HTTP host header for trust decisions. CVE-2026-87663 combines authentication bypass with command injection in the inter-switch remote execution service.

Other vulnerabilities include buffer overflows and memory read errors. CVE-2026-87671 describes an out-of-bounds memory read in the web management daemon, exploitable by unauthenticated attackers via crafted URL query parameters. CVE-2026-87668 details a stack-based buffer overflow in the diagnostic execution utility when processing command arguments. Race conditions were also identified, such as in CVE-2026-87684 and CVE-2026-94583, affecting the web management daemon and REST management interface respectively, potentially leading to unpredictable behavior during concurrent request processing.

The patched versions for all these vulnerabilities are 9.2.2d and 10.0.0a1 for some, and 10.0.1 for others, with the latter addressing the full set of disclosed issues. Broadcom has released version 10.0.1 to fix all 19 vulnerabilities. Users are strongly recommended to upgrade to version 10.0.1 to mitigate the risks associated with these critical flaws, which could lead to unauthorized access, command execution, and disruption of fabric services.

This batch of disclosures underscores the importance of timely patching for Fabric OS, as the identified vulnerabilities span multiple attack vectors and affect core management functionalities. The concentration of high-severity flaws, particularly those allowing command injection and authorization bypass, presents a significant risk to the integrity and security of storage networks managed by Brocade Fabric OS.

Key Findings:

  • Nineteen vulnerabilities were disclosed simultaneously for Broadcom Fabric OS, affecting versions prior to 10.0.1.
  • Multiple high-severity flaws include OS command injection, privilege escalation, and authorization bypass.
  • Vulnerabilities impact various components, including REST API, web interfaces, CLI, and inter-switch communication.
  • Patches are available in Fabric OS versions 9.2.2d, 10.0.0a1, and 10.0.1, with 10.0.1 addressing all disclosed issues.
  • Urgent upgrades are recommended to prevent unauthorized access and command execution.
  • The disclosure occurred on October 8, 2026, within a four-hour window.

CVEs addressed include CVE-2026-94586, CVE-2026-94581, CVE-2026-94579, CVE-2026-94577, CVE-2026-87663, CVE-2026-94584, CVE-2026-87688, CVE-2026-87673, CVE-2026-87666, CVE-2026-87660, CVE-2026-94583, CVE-2026-87686, CVE-2026-87678, CVE-2026-87671, CVE-2026-87668, CVE-2026-87659, CVE-2026-87682, CVE-2026-87680, and CVE-2026-87679.

Synthesized by Vypr AI
Broadcom Fabric OS: 19 Vulnerabilities Including Command Injection and Auth Bypass Disclosed Together · VYPR