Skip to content
TrustList
News

Broadcom fixes 61 Brocade Fabric OS, SANnav and ASCG flaws

Editorial

By TrustList Editorial

Thirty-seven of the 61 are rated high. ASCG carries two unauthenticated flaws reachable from the adjacent network, and Fabric OS 10.0.1 closes both a command injection and a buffer overflow.

About Broadcom fixes 61 Brocade Fabric OS, SANnav and ASCG flaws

Broadcom fixes 61 Brocade Fabric OS, SANnav and ASCG flaws

6 October 2026: Broadcom has published security updates for Brocade Fabric OS, SANnav and the ASC Gateway (ASCG) that, according to Italy's national cybersecurity agency ACN, fix 61 vulnerabilities, 37 of them rated high. ACN lists the types as arbitrary code execution, authentication bypass, privilege escalation, denial of service, tampering, and arbitrary file read, write and deletion. Its alert shows no public exploit code and no known exploitation.

Not yet independently verified. We read three of the Broadcom advisories. The count of 61 flaws and 37 high-severity ones comes from Italy's ACN, and SANnav fixed versions are not confirmed here. We will update this when it can be confirmed, and remove this note.

Fabric OS

ACN gives affected Fabric OS as anything before 10.0.1. Two of the Broadcom advisories we read show the range of what is fixed:

  • CVE-2026-87688, a command injection in the security certificate management subsystem, CVSS 4.0 score 8.5. It affects versions before 9.2.2d and 10.0.0 through 10.0.0a1. Fixed in 9.2.2d and 10.0.1.
  • CVE-2026-87679, a heap-based buffer overflow in port list parsing, also scored 8.5, affecting versions before 10.0.1. The vector requires a privileged account on the adjacent network.

Both advisories were first published on 6 October 2026.

ASC Gateway

The ASCG items are the ones to check first, because the advisories rate them as needing no authentication and no privileges. CVE-2026-85421 is a missing authentication check in the ASCGStreaming service, scored 8.7. CVE-2026-85487 is an unauthenticated path traversal, scored 8.6. Both affect the standard ASCG deployment before 3.5.0, which Broadcom ties to the Brocade ASC-Gateway OVA and Brocade Support Link. Broadcom's page for the first one gives 3.5.0 as the fixed version and lists no workaround, and the second page lists none either. The attack vector in both is the adjacent network, so exposure depends on who can reach the appliance from the management segment.

The portal shows an initial publication date of 2 October for these two while the revision history says 9 September, so the dates in the advisories disagree.

SANnav

ACN lists SANnav as affected before 2.4.0b and in version 3.0.0, and refers readers to the Broadcom advisories for fixed versions. Check the SANnav bulletins directly before planning the upgrade path.

Storage teams that run Fabric OS switches usually have a short list of maintenance windows, so the practical step is to inventory current Fabric OS, SANnav and ASCG versions against the three version lines above.

Company profile on TrustList: Broadcom

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy