ZeroHour

CVE-2026-84393

large

Certificate Host-Mismatch Validation Flaw in FortiOS and FortiProxy ZTNA

CVSS 3.1
8.1 high
EPSS
<1%p5
Published
()
Modified
AI analysis

CVE-2026-84393 is an improper certificate validation flaw (CWE-297, host mismatch) in the ZTNA (Zero Trust Network Access) functionality of Fortinet FortiOS and FortiProxy, in which certificates are not correctly verified against the intended host. Per the related advisory headline, a network-adjacent or on-path attacker can exploit it to perform a man-in-the-middle attack against ZTNA connections, and the vendor describes the impact as information disclosure; the CVSS vector additionally rates confidentiality, integrity, and availability impact as high. Organizations running affected FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 with ZTNA enabled are exposed. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (5th percentile), so risk is currently low but patching is still warranted given the high CVSS score.

What to do: Inventory FortiOS and FortiProxy deployments for versions 7.6.1–7.6.6 / 7.6.2–7.6.6 and prioritize upgrades to a fixed release listed in Fortinet's PSIRT advisory for this CVE (fixed versions are not specified in the available data). Until patched, treat ZTNA sessions on affected devices as susceptible to on-path interception and restrict or monitor ZTNA use, particularly for untrusted or public network paths. No public exploit or in-the-wild exploitation is known, so this can be handled in a normal patch cycle rather than emergency change.

Affected
Fortinet FortiOS7.6.1 through 7.6.6
Fortinet FortiProxy7.6.2 through 7.6.6
Estimated exposure
largeon the order of tens of thousands of gateways (a subset of the roughly 300,000+ internet-visible Fortinet devices, limited to those running the 7.6 branch with… — Public internet scans consistently show several hundred thousand exposed Fortinet firewalls/proxies, but only devices on the recent 7.6 release branch that actually use ZTNA are affected, so the plausible population is tens of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via

Weakness
CWE-297
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

Weekly roundup: Microsoft patches 973 flaws including two actively exploited zero-days; FortiOS CAPWAP flaw deploys PivotC2 RAT; PAN-OS root RCE disclosed.

Microsoft's September 2026 Patch Tuesday fixed 973 vulnerabilities, including two zero-days under active exploitation: CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack), both elevation-of-privilege bugs. SOCRadar reported active exploitation of CVE-2025-25249 (CVSS 9.8) in FortiOS CAPWAP, deploying a Node.js RAT called PivotC2 that exfiltrates Exchange mailboxes to Wasabi cloud storage; 178 devices were compromised out of 30,000 scanned IPs, attributed to a Russian-speaking financially motivated group. Palo Alto disclosed CVE-2026-0310, a 9.2-rated buffer overflow enabling root code execution on PA-Series firewalls, and Fortinet disclosed CVE-2026-84393, a ZTNA certificate validation MITM flaw. Cyera also revealed CVE-2026-6471 ('PostGREShell'), a 12-year-old PostgreSQL logical-decoding flaw allowing code execution via REPLICATION-privileged accounts.

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.

Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Fortinet discloses high-severity certificate validation flaw CVE-2026-84393 in FortiOS and FortiProxy Agentless ZTNA portals enabling unauthenticated man-in-the-middle attacks.

Fortinet disclosed CVE-2026-84393 (CVSSv3 7.3, CWE-295) on September 8, 2026 under advisory FG-IR-26-174: improper certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. An unauthenticated attacker on the network path could present a forged or mismatched certificate and intercept or tamper with traffic between the portal and backend destinations, with impact classified as information disclosure. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; the 8.0, 7.4 and 7.2 branches of both products are unaffected. Fortinet urges upgrading to 7.6.7 or later and reports no evidence of exploitation in the wild.