Broadcom fixes 61 Brocade Fabric OS, SANnav and ASCG flaws
EditorialBy TrustList Editorial
Thirty-seven of the 61 are rated high. ASCG carries two unauthenticated flaws reachable from the adjacent network, and Fabric OS 10.0.1 closes both a command injection and a buffer overflow.
- Data Storage
- Network Security
- Cybersecurity
- Vulnerability Management
About Broadcom fixes 61 Brocade Fabric OS, SANnav and ASCG flaws
Broadcom fixes 61 Brocade Fabric OS, SANnav and ASCG flaws
6 October 2026: Broadcom has published security updates for Brocade Fabric OS, SANnav and the ASC Gateway (ASCG) that, according to Italy's national cybersecurity agency ACN, fix 61 vulnerabilities, 37 of them rated high. ACN lists the types as arbitrary code execution, authentication bypass, privilege escalation, denial of service, tampering, and arbitrary file read, write and deletion. Its alert shows no public exploit code and no known exploitation.
Not yet independently verified. We read three of the Broadcom advisories. The count of 61 flaws and 37 high-severity ones comes from Italy's ACN, and SANnav fixed versions are not confirmed here. We will update this when it can be confirmed, and remove this note.
Fabric OS
ACN gives affected Fabric OS as anything before 10.0.1. Two of the Broadcom advisories we read show the range of what is fixed:
- CVE-2026-87688, a command injection in the security certificate management subsystem, CVSS 4.0 score 8.5. It affects versions before 9.2.2d and 10.0.0 through 10.0.0a1. Fixed in 9.2.2d and 10.0.1.
- CVE-2026-87679, a heap-based buffer overflow in port list parsing, also scored 8.5, affecting versions before 10.0.1. The vector requires a privileged account on the adjacent network.
Both advisories were first published on 6 October 2026.
ASC Gateway
The ASCG items are the ones to check first, because the advisories rate them as needing no authentication and no privileges. CVE-2026-85421 is a missing authentication check in the ASCGStreaming service, scored 8.7. CVE-2026-85487 is an unauthenticated path traversal, scored 8.6. Both affect the standard ASCG deployment before 3.5.0, which Broadcom ties to the Brocade ASC-Gateway OVA and Brocade Support Link. Broadcom's page for the first one gives 3.5.0 as the fixed version and lists no workaround, and the second page lists none either. The attack vector in both is the adjacent network, so exposure depends on who can reach the appliance from the management segment.
The portal shows an initial publication date of 2 October for these two while the revision history says 9 September, so the dates in the advisories disagree.
SANnav
ACN lists SANnav as affected before 2.4.0b and in version 3.0.0, and refers readers to the Broadcom advisories for fixed versions. Check the SANnav bulletins directly before planning the upgrade path.
Storage teams that run Fabric OS switches usually have a short list of maintenance windows, so the practical step is to inventory current Fabric OS, SANnav and ASCG versions against the three version lines above.
Company profile on TrustList: Broadcom
Sources
Categories & features
- Data Storage
- Network Security
- Cybersecurity
- Vulnerability Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More Data StorageThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.