CVE-2026-22628Disclosure(fortinet / fortiswitchaxfixed)

LOWCVSS 6.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiswitchaxfixed

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
fortiswitchaxfixed

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-18: 2Technical Details · 2026-03-18: 103-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-22628 An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specific… https://www.cve.org/CVERecord?id=CVE-2026-22628 ----- Traducción: CVE-2026-22628 Una… http://infoflow.cloud`

    Post summary

    The tweet only states that CVE-2026-22628 is an improper access control flaw in FortiSwitchAXFixed, with no further technical, exploit, or patch details.

    0000040
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22628 An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specific… https://www.cve.org/CVERecord?id=CVE-2026-22628

    Post summary

    The post announces CVE-2026-22628, describing an improper access control flaw that permits authenticated admin command execution on FortiSwitchAXFixed devices, but provides no exploit, patch, or active usage details.

    00000222
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiswitchaxfixed---

Explore more