CVE-2026-87675EPSS p53.0%
CVE-2026-87675CVE-2026-87675
Description
An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration download operation, the management daemon will relay configuration parameters, user-supplied relay host strings, and filenames directly to an internal utility script without sufficient character set validation. Because the local utility fails to sanitize shell metacharacters before processing them in a system shell command, a malicious or compromised configuration file can cause arbitrary operating system commands to be executed on a remote local switch when an administrator initiates a configuration download.
Scoring
| EPSS | 0.73% probability of exploitation · percentile 53.0% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |