Stack-based Buffer Overflow in Brocade Fabric OS IKEv2 Protocol
CVE-2026-87665

6MEDIUM

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87665?

A stack-based buffer overflow vulnerability is present in the Internet Key Exchange (IKEv2) protocol handler within Brocade Fabric OS prior to version 10.0.1. This vulnerability emerges during the processing of initial IKE key exchange requests on extension switches or blades utilizing IPsec-enabled Fibre Channel over IP (FCIP) circuits. An unauthenticated remote attacker can exploit the flaw by dispatching a specifically crafted UDP packet to port 500, which includes an oversized Nonce payload. If successfully executed, this attack can lead to a denial of service, resulting in a crash of the data-plane process.

Affected Version(s)

Fabric OS 0 < 10.0.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.