Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · broadcom

broadcom

· 61 Critical

Total CVEs

625

Critical

61

Products

270

Search All CVEs →

625

Products (270)

fabric operating system95 CVEsbrocade sannav54 CVEstcpreplay50 CVEsbrightstor arcserve backup41 CVEsbrocade fabric operating system firmware26 CVEsraid controller web interface22 CVEssannav20 CVEsbrightstor enterprise backup19 CVEsetrust antivirus16 CVEsetrust intrusion detection16 CVEsadvanced secure gateway16 CVEsbusiness protection suite16 CVEsinoculateit13 CVEsrabbitmq server13 CVEssymantec proxysg13 CVEsserver protection suite13 CVEsarcserve backup12 CVEsbrocade fabric operating system11 CVEsetrust ez antivirus11 CVEssymantec critical system protection11 CVEsbrightstor arcserve backup laptops desktops11 CVEsetrust secure content manager10 CVEsetrust ez armor10 CVEsca api developer portal10 CVEsdx netops spectrum10 CVEsprivileged access manager10 CVEsdesktop management suite10 CVEsetrust antivirus gateway9 CVEsunicenter network and systems management8 CVEsca automic automation7 CVEsunicenter asset management7 CVEssymantec data center security server7 CVEsunicenter remote control7 CVEsanti-virus for the enterprise7 CVEscommon services7 CVEsinternet security suite6 CVEsrelease automation6 CVEssymantec identity governance and administration6 CVEsetrust integrated threat management6 CVEsetrust admin6 CVEssymantec messaging gateway6 CVEsbrightstor portal5 CVEssecure content manager5 CVEsunicenter tng5 CVEslicense software5 CVEsbrightstor san manager5 CVEsdesktop protection suite5 CVEsproject portfolio management5 CVEssymantec endpoint protection4 CVEsbrocade active support connectivity gateway4 CVEsnetwork and systems management4 CVEscleverpath ecm4 CVEscleverpath olap4 CVEscleverpath predictive analysis server4 CVEscontent analysis4 CVEssymantec data center security server and agents4 CVEssymantec embedded security critical system protection4 CVEssymantec embedded security critical system protection for controllers and devices4 CVEsemulex hba manager4 CVEstotal defense4 CVEsunicenter application performance monitor4 CVEsunicenter data transport option4 CVEsunicenter jasmine4 CVEsadvantage data transport4 CVEsunicenter service level management4 CVEsunicenter software delivery4 CVEsunified infrastructure management4 CVEsarcserve backup 20003 CVEssymantec identity manager3 CVEsanti-virus sdk3 CVEsunicenter nsm wireless network management option3 CVEsunicenter performance management3 CVEsehealth3 CVEsvmware nsx-t data center3 CVEsintegrated threat management3 CVEssiteminder3 CVEsbcm4355c0 firmware3 CVEswidcomm bluetooth3 CVEsservice desk manager3 CVEscleverpath aion3 CVEsvmware nsx3 CVEsetrust antivirus webscan3 CVEscleverpath portal3 CVEsetrust security command center3 CVEsbrightstor hierarchical storage manager3 CVEsanti-virus3 CVEsadviseit3 CVEsbrightstor mobile backup3 CVEsbcm436843 CVEsbcm4355c03 CVEsspectrum2 CVEsbcm43232 CVEsbcm436942 CVEsca workload automation ae2 CVEsetrust siteminder2 CVEsbcm432242 CVEsbrcmfmac driver2 CVEsbcm431622 CVEsca client automation2 CVEsbcm43392 CVEsbcm4339 firmware2 CVEsantispyware for the enterprise2 CVEsanti-spyware2 CVEsmessaging2 CVEssymantec pgp encryption2 CVEssymantec privileged access management2 CVEserwin process modeler2 CVEssymantec siteminder2 CVEsbcm67552 CVEsbrocade network advisor2 CVEsbcm67522 CVEsetrust antivirus ee2 CVEsbcm67502 CVEsbcm67102 CVEsbcm27112 CVEsetrust pestpatrol2 CVEsunicenter management portal2 CVEsbcm476222 CVEsunicenter remote control host2 CVEssingle sign-on2 CVEssymantec advanced secure gateway s200-30 firmware1 CVEssymantec advanced secure gateway s200-401 CVEssymantec advanced secure gateway s200-40 firmware1 CVEssymantec advanced secure gateway s400-201 CVEssymantec advanced secure gateway s400-20 firmware1 CVEssymantec advanced secure gateway s400-301 CVEssymantec advanced secure gateway s400-30 firmware1 CVEssymantec advanced secure gateway s400-401 CVEssymantec advanced secure gateway s400-40 firmware1 CVEssymantec advanced secure gateway s500-201 CVEssymantec advanced secure gateway s500-20 firmware1 CVEssymantec deployment solutions1 CVEssymantec eraser engine1 CVEssymantec intelligencecenter1 CVEssymantec server management suite1 CVEssymantec siteminder webagent1 CVEssystemedge1 CVEssystems performance for infrastructure managers1 CVEsthreat manager1 CVEsunicenter asset portfolio management1 CVEsunicenter autosys jm1 CVEsunicenter remote control option1 CVEsunicenter service delivery1 CVEsunicenter service desk1 CVEsunicenter service desk knowledge tools1 CVEsunicenter service fulfillment1 CVEsunicenter service metric analysis1 CVEsunicenter serviceplus service desk1 CVEsvmware ace management server1 CVEs2e web option1 CVEsxcom data transport1 CVEsadsl1 CVEsalert notification server1 CVEsanti-spyware for the enterprise1 CVEsanti virus sdk1 CVEsantivirus gateway1 CVEsantivirus sdk1 CVEsapi gateway1 CVEsarcserve client agent1 CVEsautomic workload automation1 CVEsbcm430121 CVEsbcm43012 firmware1 CVEsbcm430131 CVEsbcm43013 firmware1 CVEsbcm43251 CVEsbcm43291 CVEsbcm4335c01 CVEsbcm4335c0 firmware1 CVEsbcm4339 soc1 CVEsbcm4339 soc firmware1 CVEsbcm43438a11 CVEsbcm43438a1 firmware1 CVEsbcm43521 CVEsbcm4352 firmware1 CVEsbcm4354 wi-fi chipset1 CVEsbcm43561 CVEsbcm4356 firmware1 CVEsbcm4358 wi-fi chipset1 CVEsbcm4359 wi-fi chipset1 CVEsbcm43684 firmware1 CVEsbcm43751 CVEsbcm437521 CVEsbcm43752 firmware1 CVEsbcm4375 firmware1 CVEsbcm43891 CVEsbcm4389 firmware1 CVEsbcm43xx wi-fi chipset firmware1 CVEsbcm57801 CVEsbcmwl5.sys wireless device driver1 CVEsbitnami1 CVEsbitnami\/pgpool1 CVEsbluecoat security gateway1 CVEsbluetooth stack1 CVEsbrightstor arcserve backup hp1 CVEsbrightstor arcserve backup server1 CVEsbrightstor arcserve client1 CVEsbrightstor process automation manager1 CVEsbrightstor storage resource manager1 CVEsbrigthstor arcserve client for windows1 CVEsbroadcom1 CVEsbroadcom linux1 CVEsbrocade 3001 CVEsbrocade 6101 CVEsbrocade 65051 CVEsbrocade 65101 CVEsbrocade 65201 CVEsbrocade 65471 CVEsbrocade 78001 CVEsbrocade 78101 CVEsbrocade 78401 CVEsbrocade g6201 CVEsbrocade g6301 CVEsbrocade x6-4 director1 CVEsbrocade x6-8 director1 CVEsca automic dollar universe1 CVEsca automic sysload1 CVEsca clarity1 CVEsca harvest software change manager1 CVEsca identity governance1 CVEsca identity suite virtual appliance1 CVEsca network flow analysis1 CVEsca performance management1 CVEsca service catalog1 CVEsccc harvest1 CVEsclarity1 CVEsclient automation1 CVEscontrolit1 CVEsdirectory1 CVEserwin data model validator1 CVEsetrust access control1 CVEsetrust antivirus iris engine1 CVEsetrust antivirus sdk1 CVEsetrust audit aries1 CVEsetrust audit client1 CVEsetrust audit datatools1 CVEsetrust audit irecorder1 CVEsetrust audit policy manager1 CVEsetrust ez armor le1 CVEsetrust identity minder1 CVEsetrust internet security suite1 CVEsetrust threat management console1 CVEshardmac wi-fi soc1 CVEshardmac wi-fi soc firmware1 CVEshost-based intrusion prevention system1 CVEsigateway1 CVEsinoculan1 CVEsinoculateit agent for exchange1 CVEsinvestigation tool1 CVEsitechnology igateway1 CVEslayer7 api management oauth toolkit1 CVEslsi pci-sv92ex1 CVEslsi pci-sv92ex firmware1 CVEsmessage queuing1 CVEsmlink1 CVEsnetmaster file transfer management1 CVEsnetmaster network management for tcp\/ip1 CVEsnetwork flow analysis1 CVEsnetwork operations1 CVEsnolio1 CVEsone command manager1 CVEsoutput management web viewer1 CVEspipa c2111 CVEspipa c211 web interface1 CVEsproxysg1 CVEsresource initialization manager1 CVEsservice desk1 CVEsssl visibility appliance1 CVEssymantec advanced secure gateway 500-101 CVEssymantec advanced secure gateway 500-10 firmware1 CVEssymantec advanced secure gateway s200-301 CVEs

Recent Vulnerabilities

View all 625
CVE-2026-57219HIGH 7.5

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

CVE-2026-3862MEDIUM 4.8

Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.

CVE-2026-0869HIGH 8.8

Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric.

CVE-2025-9711HIGH 7.8

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands.

CVE-2025-58381LOW 2.3

A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories.

CVE-2025-58380LOW 2.3

A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.

CVE-2026-0383HIGH 7.8

A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command.

CVE-2025-58383HIGH 7.2

A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security controls allowing the execution of arbitrary commands.

CVE-2025-58382HIGH 7.2

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command.

CVE-2025-58379MEDIUM 5.5

Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user.

CVE-2025-12774HIGH 7.5

A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such as details of database tables and encrypted passwords.

CVE-2025-12773MEDIUM 6.5

A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the Brocade SANnav database password.

CVE-2025-12772MEDIUM 4.9

Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in clear text. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the switch admin password.

CVE-2025-12680MEDIUM 4.9

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.

CVE-2025-12679MEDIUM 6.5

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and not in a new installation. The system audit logs are accessible only to a privileged user on the server. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.

CVE-2025-69276HIGH 8.8

Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier.

CVE-2025-69275MEDIUM 6.1

Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier.

CVE-2025-69274HIGH 8.8

Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.

CVE-2025-69273HIGH 7.5

Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.

CVE-2025-69272HIGH 7.5

Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier.

CVE-2025-69271HIGH 7.5

Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier.

CVE-2025-69270CRITICAL 9.8

Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

CVE-2025-69269CRITICAL 9.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier.

CVE-2025-69268MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Reflected XSS.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

CVE-2025-69267MEDIUM 6.5

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.