CVE-2026-22628: Fortinet Fortiswitchaxfixed

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file.

Affected products

  • Fortinet Fortiswitchaxfixed: from 1.0.0, before 1.0.2 (fixed in 1.0.2)

Published 2026-03-10. Last modified 2026-06-17.