ZeroHour

Search: “agentless”

104 stories

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Fortinet discloses high-severity certificate validation flaw CVE-2026-84393 in FortiOS and FortiProxy Agentless ZTNA portals enabling unauthenticated man-in-the-middle attacks.

Fortinet disclosed CVE-2026-84393 (CVSSv3 7.3, CWE-295) on September 8, 2026 under advisory FG-IR-26-174: improper certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. An unauthenticated attacker on the network path could present a forged or mismatched certificate and intercept or tamper with traffic between the portal and backend destinations, with impact classified as information disclosure. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; the 8.0, 7.4 and 7.2 branches of both products are unaffected. Fortinet urges upgrading to 7.6.7 or later and reports no evidence of exploitation in the wild.

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.

Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.

SecurityWeekupdated · 6d agofirst · 6d agoVulnerability 4 sourcesCVE-2026-84390CVE-2026-84388CVE-2026-26084+1 CVEs