CVE-2026-85486EPSS p12.5%
CVE-2026-85486CVE-2026-85486
Description
Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application.
Scoring
| EPSS | 0.23% probability of exploitation · percentile 12.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |