CVE-2026-22627Patch(fortinet / fortiswitchaxfixed)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fortinet fortiswitchaxfixed systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiswitchaxfixed

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-10); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
fortiswitchaxfixed

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-10: 3Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 3Technical Details · 2026-03-11: 1Technical Details · 2026-03-18: 103-1003-1103-1303-18
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-103
Disclosure1Patch2
2026-03-111
Patch1
2026-03-131
General1
2026-03-181
Disclosure1
Full discourse6 posts
  • Machina Record@MachinaRecord
    Patch

    🩹マイクロソフト、2026年3月の月例パッチで脆弱性79件を修正 Copilot Agentの武器化に悪用可能なゼロクリック脆弱性も(CVE-2026-26144他) 🔨Fortinet、深刻度の高い脆弱性数件について注意喚起(CVE-2026-22627、CVE-2026-24017他) 〜サイバーアラート3月11日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44493/

    Post summary

    The post announces Microsoft’s 2026 March patch covering 79 vulnerabilities and reports Fortinet’s advisory for several high‑severity CVEs, emphasizing the availability of vendor patches rather than active exploitation or PoC details.

    02010278
    1.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年3月ぱっちちゅーずーでー ▼Microsoft 2026 年 3 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/03/202603-security-update CVE-2026-26127 .NET のサービス拒否の脆弱性 CVE-2026-21262 SQL サーバーの特権の昇格の脆弱性 ▼SAP SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html CVE-2019-17571 SAP Quotation Management Insurance アプリケーション (FS-QUO) におけるコードインジェクションの脆弱性 CVE-2026-27685 SAP NetWeaver Enterprise Portal 管理における安全でないデシリアライゼーション ▼Ivanti(critical系はなし) March 2026 Security Update https://www.ivanti.com/blog/march-2026-security-update CVE-2026-3483 バージョン 2026.1.1 より前の Ivanti DSM で公開されている危険な方法により、ローカルで認証された攻撃者が権限を昇格できる可能性 ▼Fortinet(critical系はなし) https://fortiguard.fortinet.com/psirt CVE-2026-22627 LLDP OUIフィールドのバッファオーバーフロー CVE-2025-54820 fgtupdates サービスによるバッファオーバーフロー ▼Adobe https://helpx.adobe.com/security.html

    Post summary

    The post catalogs newly released CVEs across major vendors and confirms that security patches are available, providing concise details of each vulnerability type.

    100201.1K
    11.4K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Fortinet ❗ CVE-2026-24018 ❗ CVE-2026-24017 ❗ CVE-2026-22627 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-fortinet-8/ https://t.co/b7lKkphDE9

    Post summary

    The tweet merely lists three Fortinet CVEs and directs readers to a link for more details, offering no evidence of PoC, exploitation, patches, or false‑positive claims.

    00010125
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22627 A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated… https://www.cve.org/CVERecord?id=CVE-2026-22627

    Post summary

    CVE-2026-22627 is announced as a classic buffer overflow in Fortinet FortiSwitchAXFixed 1.0.0‑1.0.1, providing basic technical details but no evidence of exploitation or patch information.

    00000201
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-22627: HIGH] Critical buffer overflow vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 could allow remote attackers to execute unauthorized code. Update immediately to secure your d...#cve,CVE-2026-22627,#cybersecurity https://cvefind.com/CVE-2026-22627

    Post summary

    A highly severe buffer overflow in Fortinet FortiSwitchAXFixed 1.0.0‑1.0.1 is disclosed; the post urges users to update immediately.

    0000043
    601 followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-22627 PT-Identifier: PT-2026-24240 Vendor: Fortinet Product: FortiSwitchAXFixed CVSS: 7.7 Credits: n/a Description: A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-22627 • https://fortiguard.fortinet.com/psirt/FG-IR-26-086 #dbugs_vuln

    Post summary

    The post announces a buffer‑overflow vulnerability (CVE-2026-22627) in Fortinet FortiSwitchAXFixed that allows code execution via crafted LLDP packets, but no exploitation, patch, or PoC details are provided.

    0000056
    557 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiswitchaxfixed---

Explore more