OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-87673 (CVSS 7.0)

NVD · officialPublished Oct 8, 2026Risk 23/100

An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The binary fails to sanitize user-supplied input options when invoking underlying system commands through a shell interpreter. A privileged user with maintenance account access can exploit this issue by supplying crafted parameters, which results in arbitrary OS command execution with root privileges.

CVSS
7.0
AV:LocalAC:LowPR:HighUI:Passive

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source