๐Ÿ” CVE Alert

CVE-2026-85423

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector.

CWE CWE-306
Vendor brocade
Product brocade active support connectivity gateway
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for brocade brocade active support connectivity gateway

Be the first to know when new unknown vulnerabilities affecting brocade brocade active support connectivity gateway are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Brocade / Brocade Active Support Connectivity Gateway
0 < 3.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.broadcom.com: https://support.broadcom.com/external/content/SecurityAdvisories/0/38380