Broadcom has published dozens of security bulletins for Brocade Fabric OS, with 25 of the entries rated as high risk. The issues concern management, access control, and storage infrastructure functions, with the fixes primarily related to versions 10.0.1 and 9.2.2d.

Broadcom's listing groups CVEs by release that includes fixes. The list includes high- and medium-risk vulnerabilities, ranging from command injection and access control bypass to memory overflow and denial of service. The bulletins were published on October 6, 2026.
This date refers to the release of security advisories, not the release of FOS 10.0.1. Broadcom's release notes date 10.0.1 to June 25, 2026, as a maintenance release for specific generations of equipment. For some CVEs, NVD reports that versions prior to 10.0.1 are affected, but has not yet assigned a CVSS score.
What Brocade Fabric OS vulnerabilities reveal
One of the serious cases is CVE-2026-87680, which affects the REST API management interface. According to NVD, an authenticated user can send specially crafted parameters and execute commands to the operating system. Broadcom classifies the issue as high risk and points to the fix in FOS 10.0.1.
CVE -2026-87683 concerns a stack overflow in the REST API management component. NVD states that the attacker needs authenticated access to the REST API and could cause a service crash or potentially execute code within the management process. The description does not document an accountless exploit.
Additionally, CVE-2026-87681 concerns a role control bypass, while other entries describe memory overflows, weaknesses in management protocols, and issues with certificate processing. Broadcom lists separate high-risk issues covered by 10.0.1 and 9.2.2d, so there is not a single update for every device.
The vulnerabilities are in the software that manages Fibre Channel switches and storage systems. If management access is compromised, the consequences can extend beyond an individual switch, depending on its position in the network structure and the account privileges.

See also: Warning: Serious vulnerabilities in HPE Aruba CX switches
Which versions fix the gaps in Brocade Fabric OS
Broadcom maps several vulnerabilities to FOS version 10.0.1, while another group lists both 10.0.1 and 9.2.2d. There is also a separate entry for the MXG610 model, with a fix in 9.2.2d. Administrators should consult the company's CVE table and confirm which version applies to their model.
The 10.0.1 release notes list support for Gen 7 and Gen 8 platforms, but also different upgrade paths depending on the current version. For example, some upgrades from 9.2.1x are disruptive, while direct migration from 9.2.0x is not supported. Broadcom refers to intermediate steps, so testing is required before any change.
Organizations using SANnav or maintaining older configurations should also read the release prerequisites and limitations. Applying an update without a compatibility check may cause downtime or require additional preparation, especially in production environments.

What should administrators do?
The SecNews technical team recommends that administrators first record the exact model, current Brocade Fabric OS version, and SANnav version where it is used. Then, they should match the device to Broadcom CVEs and patch releases, rather than relying solely on the generic version number.
Before installation, review the supported upgrade path, schedule an appropriate maintenance window, and verify configuration backups. Until the update is complete, limiting access to management interfaces and using accounts with strictly necessary privileges reduces exposure, but is not a substitute for remediation.
Security teams can also review logs for unusual use of credentialed accounts and the REST API. This review helps identify potential abuse of the management interface while the upgrade is being orchestrated, but is not a substitute for installing the appropriate patch.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Broadcom's bulletin summary page does not list these vulnerabilities as being actively exploited. However, the high-risk listings and capabilities described for the REST API warrant early evaluation. The correct version depends on the hardware and upgrade history of each installation.
See also: CISA: Broadcom Fabric OS, CommVault and Active! vulnerabilities in the KEV Catalog
See also: Cisco patches vulnerabilities in Nexus Switches
