Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.
Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.
- CVE-2026-84390 (CVSS 9.6) enables JWT forgery to bypass FortiMonitorOnSight authentication
- CVE-2026-84388 (CVSS 9.1) lets attackers proxy browser traffic through the FortiPAM Chrome extension
- Fix requires coordinated upgrades of FortiPAM and extension 8.0.1.123+
- High-severity fixes also cover FortiSandbox info disclosure and ZTNA portal MitM
- No mention of in-the-wild exploitation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-26084 | Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days. Do: Upgrade all FortiSandbox deployments to a fixed release outside the affected ranges — later than 5.0.5 on the 5.0 branch, later than 4.4.8 on the 4.4 branch, and later than 5.0.5 for Cloud and PaaS — following Fortinet's PSIRT advisory. Until patched, restrict HTTP/HTTPS management access to the appliance to trusted management networks or VPN, since the flaw is reachable without authentication. Monitor Fortinet's advisory and the CISA KEV catalog for updates, given the critical severity score. | 9.9 | <1% |
| moderatelikely on the order of several thousand to ~10,000 deployed FortiSandbox appliances/instances worldwide, with only a smaller subset exposing the vulnerable web… | ||
| CVE-2026-84388 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-84390 | Sensitive Information in Source Code in Fortinet FortiMonitorOnSight (CVSS 9.8) CVE-2026-84390 is a critical (CVSS 3.1: 9.8) information-disclosure flaw in Fortinet FortiMonitorOnSight in which sensitive information is included in the product's source code (CWE-540). An unauthenticated, network-located attacker who obtains that embedded material (e.g., secrets or credentials shipped with the code) can use it to gain improper access by subverting access controls; the CVSS vector requires no privileges or user interaction and rates the impact high on confidentiality, integrity, and availability. All FortiMonitorOnSight deployments running the affected 7.2.x releases listed by Fortinet (7.2.0 through 7.2.2 and 7.2.4 through 7.2.7) are affected. Fortinet has shipped fixes for this flaw, but there is no public proof-of-concept, the vulnerability is not in CISA KEV, and no exploitation in the wild is currently known. Do: Upgrade FortiMonitorOnSight to a fixed release per Fortinet's PSIRT advisory, i.e., any version superseding the listed 7.2.0-7.2.2 and 7.2.4-7.2.7 ranges. Because the flaw involves sensitive material in source code, also rotate any credentials, keys, or secrets associated with the deployment and review logs for signs of unauthenticated access. Until patched, restrict network exposure of the OnSight management interface to trusted networks only. | 9.8 | — |
| nichelikely on the order of a few thousand deployments worldwide (estimate; no public install counts) | ||
| CVE-2026-84393 | Certificate Host-Mismatch Validation Flaw in FortiOS and FortiProxy ZTNA CVE-2026-84393 is an improper certificate validation flaw (CWE-297, host mismatch) in the ZTNA (Zero Trust Network Access) functionality of Fortinet FortiOS and FortiProxy, in which certificates are not correctly verified against the intended host. Per the related advisory headline, a network-adjacent or on-path attacker can exploit it to perform a man-in-the-middle attack against ZTNA connections, and the vendor describes the impact as information disclosure; the CVSS vector additionally rates confidentiality, integrity, and availability impact as high. Organizations running affected FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 with ZTNA enabled are exposed. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (5th percentile), so risk is currently low but patching is still warranted given the high CVSS score. Do: Inventory FortiOS and FortiProxy deployments for versions 7.6.1–7.6.6 / 7.6.2–7.6.6 and prioritize upgrades to a fixed release listed in Fortinet's PSIRT advisory for this CVE (fixed versions are not specified in the available data). Until patched, treat ZTNA sessions on affected devices as susceptible to on-path interception and restrict or monitor ZTNA use, particularly for untrusted or public network paths. No public exploit or in-the-wild exploitation is known, so this can be handled in a normal patch cycle rather than emergency change. | 8.1 | <1% |
| largeon the order of tens of thousands of gateways (a subset of the roughly 300,000+ internet-visible Fortinet devices, limited to those running the 7.6 branch with… |
Full article312 words · extracted from securityweek.com · click to collapse
Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects.
The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is described as an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal.
A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT).
The second critical vulnerability is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension, tracked as CVE-2026-84388 (CVSS score of 9.1).
A remote, unauthenticated attacker may exploit the security defect to proxy a user’s browser traffic if the user visits a malicious website, Fortinet explains.
“Remediation for this issue required coordinated changes in two components: FortiPAM and the Fortinet Privileged Access Agent Chrome extension. To be fully secure, customers should upgrade FortiPAM to 1.9.1 or 1.8.4, and ensure the Chrome extension is at version 8.0.1.123 or above,” the company notes.
Advertisement. Scroll to continue reading.
Fortinet also patched high-severity bugs in FortiSandbox (CVE-2026-26084) and FortiOS and FortiProxy Agentless ZTNA portal (CVE-2026-84393) that could allow attackers to access sensitive information and perform man-in-the-middle (MitM) attacks, respectively.
The remaining vulnerabilities resolved on Tuesday are medium- and low-severity issues in FortiManager, FortiAnalyzer, FortiSandbox, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy, and FortiPAM.
Successful exploitation of these flaws could allow attackers to bypass approval workflows, cause a denial-of-service (DoS) condition, execute arbitrary code, inject broadcast messages, terminate processes, crash the httpsd daemon, and cause redirections to arbitrary sites.
Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page.
Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Related: Ivanti Patches Critical Flaws Across Enterprise Security Products
Related: Chrome 153 Patches Seventh Zero-Day of 2026
Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/