Brocade Fabric OS: 19 Vulnerabilities Including High-Severity Flaws Disclosed Together
Key findings • 19 vulnerabilities disclosed simultaneously for Brocade Fabric OS versions prior to 10.0.1. • Multiple high-severity flaws include authorization bypass, command injection, and …

Key findings
- 19 vulnerabilities disclosed simultaneously for Brocade Fabric OS versions prior to 10.0.1.
- Multiple high-severity flaws include authorization bypass, command injection, and buffer overflows.
- Vulnerabilities affect REST API, web interfaces, AAA, FSPF, and IKEv2 protocols.
- Patch version 10.0.1 addresses all disclosed security issues.
- Urgent upgrade recommended to mitigate risks of unauthorized access and command execution.
On October 8, 2026, a significant batch of 19 vulnerabilities was disclosed for Brocade Fabric OS, all affecting versions prior to 10.0.1. This coordinated disclosure event highlights critical security weaknesses across various components of the operating system, including its management interfaces, network protocols, and core security frameworks. The vulnerabilities range in severity, with a notable cluster of high-severity flaws, underscoring the urgent need for administrators to apply patches.
Several vulnerabilities center on the management interfaces, both REST and web-based. CVE-2026-87670 and CVE-2026-87669 detail authorization logic flaws in the REST API gateway, allowing authenticated users to gain unauthorized access to restricted management endpoints and retrieve sensitive monitoring data. Similarly, CVE-2026-87683 describes multiple stack-based buffer overflows within the REST API management component due to improper validation of array counts in request payloads. The web server management interface is also impacted, with CVE-2026-87686 enabling authentication and access control bypass by manipulating the HTTP host header, and CVE-2026-87678 presenting an input validation and output encoding flaw in the Federated Authentication configuration. Furthermore, CVE-2026-87672 points to an information disclosure vulnerability in the SupportLink diagnostic utilities, where proxy URLs are stored insecurely. CVE-2026-87679 involves a heap-based buffer overflow during trunk configuration processing. CVE-2026-87680 and CVE-2026-87682 highlight command injection vulnerabilities within the REST API and management interfaces, respectively, allowing authenticated users to execute arbitrary system commands. CVE-2026-87676, a stack-based buffer overflow in the security library, arises from improper certificate validation. CVE-2026-87671, an out-of-bounds memory read in the web management daemon, can be exploited by unauthenticated attackers.
A significant number of high-severity flaws relate to authorization and access control bypass. CVE-2026-87659 describes a critical authorization bypass in the Management Server, allowing a compromised switch to gain administrative access via crafted Fibre Channel CT management requests. CVE-2026-87578, a high-severity authorization logic vulnerability in the AAA framework, permits remote authenticated users to achieve root-equivalent chassis access by returning crafted VSAs. CVE-2026-87681 details an Access Control Bypass in the RBAC validation engine, enabling authenticated users to perform unauthorized operations.
Several vulnerabilities impact network protocols and core components. CVE-2026-87668 describes a stack-based buffer overflow in the diagnostic execution utility due to improper tokenization of user-supplied input. CVE-2026-87665 points to a stack-based buffer overflow in the IKEv2 protocol handler, specifically affecting IPsec-enabled FCIP circuits. CVE-2026-87658 involves a memory buffer overflow in the Fabric Shortest Path First (FSPF) protocol's internal diagnostic routines. Lastly, CVE-2026-94583, a low-severity race condition, exists in the REST management interface's request processing logic.
All disclosed vulnerabilities affect Brocade Fabric OS versions prior to 10.0.1. The vendor has released version 10.0.1 as a patch to address these security issues. Users are strongly advised to upgrade to version 10.0.1 or later to mitigate these risks.
This extensive batch of vulnerabilities, disclosed simultaneously, highlights critical weaknesses in Brocade Fabric OS that could allow for unauthorized access, command execution, and denial-of-service conditions. Prompt patching is essential for maintaining the security and integrity of storage area networks managed by this operating system.