CVE-2026-85487EPSS p9.7%
CVE-2026-85487CVE-2026-85487
Description
A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restrictions to arbitrary file read, file write, or file deletion operations.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 9.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |