CISA Adds Critical Brocade Fabric OS Vulnerability to Known Exploited Vulnerabilities Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a serious security flaw in Broadcom’s Brocade Fabric OS to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting the urgent need for patching across both enterprise and government systems.
Vulnerability Details — CVE-2025-1976
Tracked as CVE-2025-1976, this high-severity vulnerability is a code injection flaw with a CVSS base score of 8.6. It allows local attackers with administrative privileges to execute arbitrary code with full root access, potentially leading to complete compromise of the storage network infrastructure—posing severe risks to data integrity and system operations.
The flaw affects Brocade Fabric OS versions 9.1.0 through 9.1.1d6. Although direct root access was removed in these releases as a security measure, improper validation of IP addresses within the OS enables an authenticated admin user to bypass protections and inject malicious code.
Technical Context
This vulnerability falls under CWE-94: Improper Control of Generation of Code (‘Code Injection’), where external input is improperly handled when constructing code, leading to unintended execution or privilege escalation. In this case, an attacker could not only run arbitrary commands but also modify core system components—potentially embedding persistent backdoors.
Exploitation Risk
Exploitation requires local access and administrative credentials, but in environments where such credentials are loosely managed or shared, the risk increases significantly. The attack requires no user interaction or complex chaining, making it easier to exploit and heightening its threat level.
Risk Overview
The vulnerability affects Brocade Fabric OS versions 9.1.0 through 9.1.1d6 and poses a significant security threat. It enables a local user with administrative privileges to execute arbitrary code with full root access, potentially leading to total system compromise. Successful exploitation requires local access and admin-level credentials, with no need for user interaction or complex attack vectors. The flaw carries a CVSS v3.1 base score of 8.6, classifying it as high severity.
CISA Confirms Active Exploitation of Brocade Fabric OS Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-1976 to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed reports of active exploitation in the wild.
According to recent security advisories and threat intelligence, attackers are successfully exploiting this vulnerability to gain root-level access on vulnerable Brocade Fabric OS systems. Although no public proof-of-concept code has been released, ongoing exploitation activity significantly increases the urgency for mitigation.
The KEV Catalog—established under Binding Operational Directive (BOD) 22-01)—prioritizes vulnerabilities that pose substantial risk to federal and critical infrastructure. As such, Federal Civilian Executive Branch (FCEB) agencies are required to remediate CVE-2025-1976 by May 19, 2025. CISA also strongly encourages private sector organizations to take immediate action, as the vulnerability could enable lateral movement and broader network compromise.
Mitigation and Response Guidance
Broadcom has issued a security advisory and released a patched version—Brocade Fabric OS 9.1.1d7—which fully addresses the vulnerability.
Organizations should upgrade to this patched version without delay. For environments where immediate patching is not possible, the following interim measures are strongly recommended:
- Restrict and audit administrative access
- Enforce strict role-based access controls
- Monitor privileged account activity for anomalies
- Isolate Fabric OS systems from less trusted or external networks
- Continuously review system logs for signs of unauthorized behavior
This incident underscores the critical importance of timely patch management, strong access controls, and proactive monitoring to defend against threats targeting core infrastructure systems.




