CVE-2026-87662
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings. When processing upgrade requests, parameters are converted into system command strings and executed through a system shell interface. Because control characters and shell metacharacters in fields like the host or file path are not stripped or sanitized, an attacker can execute arbitrary shell commands with the firmware management daemon's elevated privileges.
| CWE | CWE-78 |
| Vendor | brocade |
| Product | fabric os |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for brocade fabric os
Be the first to know when new unknown vulnerabilities affecting brocade fabric os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Brocade / Fabric OS
0 < 9.2.2d 10.0.0 โค 10.0.0a1