MajorCritical vulnerability
CVE-2026-85487 (CVSS 8.6)
NVD · officialPublished Oct 8, 2026Risk 37/100
A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restrictions to arbitrary file read, file write, or file deletion operations.
Technical details
CVSS
8.6
AV:AdjacentAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source