ZeroHour
Fortinet PSIRTpublished ()ingested

ZTNA Portal Improper Certificate Validation

highAdvisoryimportance 48
AI summary · glm-5.3

Fortinet fixed an improper certificate validation flaw (CVSS 7.3) in FortiOS and FortiProxy Agentless ZTNA portal enabling unauthenticated man-in-the-middle attacks on backend traffic.

Fortinet advisory FG-IR-26-174 discloses an improper certificate validation vulnerability (CWE-295) in the FortiOS and FortiProxy Agentless ZTNA portal, rated CVSSv3 7.3. A remote and unauthenticated attacker can perform a man-in-the-middle attack on the communication channel between the ZTNA portal and the backend destination website. The advisory was revised on 2026-09-08.

  • CVSSv3 7.3 improper certificate validation (CWE-295)
  • Affects FortiOS and FortiProxy Agentless ZTNA portal
  • Remote unauthenticated attacker can perform MITM on backend traffic
Full article

CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.