ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Fortinet Patches Critical FortiMonitorOnSight JWT Bypass (CVE-2026-84390) and FortiPAM Chrome Extension Flaw (CVE-2026-84388) Enabling Browser Proxy Control and Tab Recording

What's new: Initial merged summary (no previous version). Combines GBHackers' technical analysis of the FortiPAM extension flaw with SecurityWeek's broader patch coverage, adding CVE-2026-84390 (FortiMonitorOnSight, CVSS 9.6), the 10-vulnerability total, additional fixed CVEs (CVE-2026-26084, CVE-2026-84393), coordinated upgrade requirements (FortiPAM 1.9.1/1.8.4, extension 8.0.1.123+), and the timing…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Fortinet's patch batch fixes 10 vulnerabilities, including two critical authentication flaws: CVE-2026-84390 (CVSS 9.6), a JWT-based authentication bypass in the FortiMonitorOnSight web portal, and CVE-2026-84388 (CVSS 9.1), a FortiPAM Chrome extension flaw…

SecurityWeek reports Fortinet's patch release fixes 10 vulnerabilities across its product line, headlined by two critical authentication flaws. CVE-2026-84390 (CVSS 9.6) is a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 (CVSS 9.1) is an improper authentication flaw in the Fortinet Privileged Access Agent (FortiPAM) Chrome extension, which SecurityWeek says allows attackers to proxy a user's browser traffic via a malicious website. GBHackers adds technical detail: a webRequest listener trusts requested hostnames without validating the initiator, letting attacker-controlled domains pose as FortiPAM servers, and a second issue exposes the extension's message interface to all URLs while accepting non-JWT tokens without validation, enabling unauthenticated session launches, proxy manipulation, tab control and recording; the consent dialog can also be auto-accepted via shadow-root clicks. SecurityWeek notes remediation requires coordinated upgrades to FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. The batch also includes high-severity fixes for FortiSandbox information disclosure (CVE-2026-26084) and a man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393), plus medium/low issues in FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. The sources differ on timing: GBHackers says Fortinet issued advisory FG-IR-26-168 after a July 17 report and released the extension fix on August 1, 2026, while SecurityWeek frames the fixes within Fortinet's September patch release. Both agree there is no confirmed in-the-wild exploitation.

  • CVE-2026-84390 (CVSS 9.6): sensitive-information issue in the FortiMonitorOnSight web portal allowing unauthenticated authentication bypass with forged or reused JWTs (SecurityWeek).
  • CVE-2026-84388 (CVSS 9.1): improper authentication flaw in the Fortinet Privileged Access Agent (FortiPAM) Chrome extension (SecurityWeek).
  • Mechanism per GBHackers: a webRequest listener adds requested hostnames without verifying the initiator, letting attacker-controlled domains be trusted as FortiPAM servers; the extension's message interface is exposed to all URLs…
  • Impact: unauthenticated session launches, proxy manipulation, tab control and recording (GBHackers); proxying a user's browser traffic through the extension via a malicious website (SecurityWeek).
  • The consent dialog, rendered in the page DOM, can be auto-accepted via shadow-root clicks (GBHackers).
  • Remediation requires coordinated upgrades: FortiPAM 1.9.1/1.8.4 and Chrome extension 8.0.1.123+ (SecurityWeek).
  • Timing discrepancy: GBHackers dates the extension fix to August 1, 2026 under advisory FG-IR-26-168 after a July 17 report; SecurityWeek describes the fixes as part of Fortinet's September patch release.
  • SecurityWeek counts 10 vulnerabilities fixed in total, including high-severity FortiSandbox information disclosure (CVE-2026-26084) and a FortiOS/FortiProxy Agentless ZTNA portal MitM risk (CVE-2026-84393), plus medium/low issues in…

Coverage timeline

  1. · 6d ago
    GBHackers· 48
    FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs

    Fortinet patched CVE-2026-84388 (CVSS 9.1) in its FortiPAM Chrome extension, letting malicious websites alter proxy settings, open tabs and record sessions.

  2. · 6d ago
    SecurityWeek· 58
    Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

    Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26084
Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data

CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.

Do: Upgrade all FortiSandbox deployments to a fixed release outside the affected ranges — later than 5.0.5 on the 5.0 branch, later than 4.4.8 on the 4.4 branch, and later than 5.0.5 for Cloud and PaaS — following Fortinet's PSIRT advisory. Until patched, restrict HTTP/HTTPS management access to the appliance to trusted management networks or VPN, since the flaw is reachable without authentication. Monitor Fortinet's advisory and the CISA KEV catalog for updates, given the critical severity score.

9.9<1%
  • Fortinet FortiSandbox 5.0.0 through 5.0.5
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
  • Fortinet FortiSandbox Cloud 5.0.4 through 5.0.5
  • +1 more
moderatelikely on the order of several thousand to ~10,000 deployed FortiSandbox appliances/instances worldwide, with only a smaller subset exposing the vulnerable web…
CVE-2026-84388

NVD description · AI analysis pending
CVE-2026-84390
Sensitive Information in Source Code in Fortinet FortiMonitorOnSight (CVSS 9.8)

CVE-2026-84390 is a critical (CVSS 3.1: 9.8) information-disclosure flaw in Fortinet FortiMonitorOnSight in which sensitive information is included in the product's source code (CWE-540). An unauthenticated, network-located attacker who obtains that embedded material (e.g., secrets or credentials shipped with the code) can use it to gain improper access by subverting access controls; the CVSS vector requires no privileges or user interaction and rates the impact high on confidentiality, integrity, and availability. All FortiMonitorOnSight deployments running the affected 7.2.x releases listed by Fortinet (7.2.0 through 7.2.2 and 7.2.4 through 7.2.7) are affected. Fortinet has shipped fixes for this flaw, but there is no public proof-of-concept, the vulnerability is not in CISA KEV, and no exploitation in the wild is currently known.

Do: Upgrade FortiMonitorOnSight to a fixed release per Fortinet's PSIRT advisory, i.e., any version superseding the listed 7.2.0-7.2.2 and 7.2.4-7.2.7 ranges. Because the flaw involves sensitive material in source code, also rotate any credentials, keys, or secrets associated with the deployment and review logs for signs of unauthenticated access. Until patched, restrict network exposure of the OnSight management interface to trusted networks only.

9.8
  • Fortinet FortiMonitorOnSight 7.2.0 through 7.2.2
  • Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7
nichelikely on the order of a few thousand deployments worldwide (estimate; no public install counts)
CVE-2026-84393
Certificate Host-Mismatch Validation Flaw in FortiOS and FortiProxy ZTNA

CVE-2026-84393 is an improper certificate validation flaw (CWE-297, host mismatch) in the ZTNA (Zero Trust Network Access) functionality of Fortinet FortiOS and FortiProxy, in which certificates are not correctly verified against the intended host. Per the related advisory headline, a network-adjacent or on-path attacker can exploit it to perform a man-in-the-middle attack against ZTNA connections, and the vendor describes the impact as information disclosure; the CVSS vector additionally rates confidentiality, integrity, and availability impact as high. Organizations running affected FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 with ZTNA enabled are exposed. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (5th percentile), so risk is currently low but patching is still warranted given the high CVSS score.

Do: Inventory FortiOS and FortiProxy deployments for versions 7.6.1–7.6.6 / 7.6.2–7.6.6 and prioritize upgrades to a fixed release listed in Fortinet's PSIRT advisory for this CVE (fixed versions are not specified in the available data). Until patched, treat ZTNA sessions on affected devices as susceptible to on-path interception and restrict or monitor ZTNA use, particularly for untrusted or public network paths. No public exploit or in-the-wild exploitation is known, so this can be handled in a normal patch cycle rather than emergency change.

8.1<1%
  • Fortinet FortiOS 7.6.1 through 7.6.6
  • Fortinet FortiProxy 7.6.2 through 7.6.6
largeon the order of tens of thousands of gateways (a subset of the roughly 300,000+ internet-visible Fortinet devices, limited to those running the 7.6 branch with…