FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
Fortinet discloses high-severity certificate validation flaw CVE-2026-84393 in FortiOS and FortiProxy Agentless ZTNA portals enabling unauthenticated man-in-the-middle attacks.
Fortinet disclosed CVE-2026-84393 (CVSSv3 7.3, CWE-295) on September 8, 2026 under advisory FG-IR-26-174: improper certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. An unauthenticated attacker on the network path could present a forged or mismatched certificate and intercept or tamper with traffic between the portal and backend destinations, with impact classified as information disclosure. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; the 8.0, 7.4 and 7.2 branches of both products are unaffected. Fortinet urges upgrading to 7.6.7 or later and reports no evidence of exploitation in the wild.
- No authentication is required, raising risk for internet-facing or semi-trusted ZTNA portal deployments.
- FortiOS and FortiProxy 8.0, 7.4 and 7.2 branches are confirmed unaffected.
- The flaw is not currently listed as a known exploited vulnerability.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84393 | Certificate Host-Mismatch Validation Flaw in FortiOS and FortiProxy ZTNA CVE-2026-84393 is an improper certificate validation flaw (CWE-297, host mismatch) in the ZTNA (Zero Trust Network Access) functionality of Fortinet FortiOS and FortiProxy, in which certificates are not correctly verified against the intended host. Per the related advisory headline, a network-adjacent or on-path attacker can exploit it to perform a man-in-the-middle attack against ZTNA connections, and the vendor describes the impact as information disclosure; the CVSS vector additionally rates confidentiality, integrity, and availability impact as high. Organizations running affected FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 with ZTNA enabled are exposed. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (5th percentile), so risk is currently low but patching is still warranted given the high CVSS score. Do: Inventory FortiOS and FortiProxy deployments for versions 7.6.1–7.6.6 / 7.6.2–7.6.6 and prioritize upgrades to a fixed release listed in Fortinet's PSIRT advisory for this CVE (fixed versions are not specified in the available data). Until patched, treat ZTNA sessions on affected devices as susceptible to on-path interception and restrict or monitor ZTNA use, particularly for untrusted or public network paths. No public exploit or in-the-wild exploitation is known, so this can be handled in a normal patch cycle rather than emergency change. | 8.1 | <1% |
| largeon the order of tens of thousands of gateways (a subset of the roughly 300,000+ internet-visible Fortinet devices, limited to those running the 7.6 branch with… |
Full article461 words · extracted from cybersecuritynews.com · click to collapse
Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website.
Tracked as CVE-2026-84393 and documented under advisory FG-IR-26-174, the issue was published on September 8, 2026, and carries a CVSSv3 score of 7.3.
The vulnerability stems from an improper certificate validation weakness, classified as CWE-295, within the Agentless ZTNA portal component. Zero Trust Network Access portals are designed to broker secure, identity-verified connections between end users and internal applications without requiring a full VPN client.
When certificate validation on the backend connection doesn’t properly enforce certificate validation, an attacker on the network path can present a forged or mismatched certificate and go undetected.
This opens the door to a classic man-in-the-middle scenario, where the attacker sits between the ZTNA portal and the destination website, silently observing or tampering with the session while both endpoints believe the connection is trusted.
Fortinet has classified the resulting impact as information disclosure, since a successful attacker could potentially view sensitive data traversing the compromised channel, including session details or application content, without needing any authentication credentials.
The attack vector is unauthenticated, meaning no prior access or valid login is required, which increases the practical risk for organizations that expose ZTNA portals to less trusted network segments.
The bug affects a fairly narrow band of releases. On the FortiOS side, versions 7.6.1 through 7.6.6 are vulnerable, while FortiOS 8.0, 7.4, and 7.2 branches are confirmed unaffected. FortiProxy carries a similar footprint, with versions 7.6.2 through 7.6.6 exposed, while FortiProxy 8.0, 7.4, and 7.2 remain unaffected.
Fortinet’s recommended remediation is straightforward: administrators running the affected 7.6 branch of either product should upgrade to version 7.6.7 or later. The vendor has also pointed customers toward its official upgrade path tool to help plan a smooth migration without disrupting existing ZTNA policies.
There is currently no evidence that CVE-2026-84393 has been exploited in the wild, and Fortinet’s tracking confirms it is not listed as a known exploited vulnerability at this time.
Because ZTNA portals are typically internet-facing or exposed to semi-trusted zones by design, organizations relying on Agentless ZTNA in FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 should prioritize patching to 7.6.7 promptly rather than treating this as a routine maintenance update, since the unauthenticated attack path meaningfully increases exposure until remediation is complete.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/fortios-and-fortiproxy-ztna-validation-vulnerability/