CVE-2026-85490
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthenticated remote attacker capable of sending or intercepting ingested archive files can leverage this flaw to write arbitrary files to restricted locations on the underlying host, potentially leading to remote code execution.
| CWE | CWE-22 |
| Vendor | brocade |
| Product | brocade active support connectivity gateway |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for brocade brocade active support connectivity gateway
Be the first to know when new unknown vulnerabilities affecting brocade brocade active support connectivity gateway are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Brocade / Brocade Active Support Connectivity Gateway
0 < 3.5.0