Junglewise Threat Intelligence

CVE-2026-84393: Fortinet FortiOS and FortiProxy certificate validation bypass in ZTNA portal

CVE-2026-84393 · Severity: high · CVSS 8.1 · Published 2026-09-08

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

Fortinet's FortiOS and FortiProxy include an Agentless Zero Trust Network Access (ZTNA) portal that validates SSL certificates to secure communication with backend websites. Due to improper certificate validation, an unauthenticated attacker can intercept and modify traffic between the portal and backend systems, potentially exposing sensitive information or performing account takeover attacks.

Technical details

This vulnerability is a certificate validation flaw (CWE-295) in the ZTNA portal component that fails to properly validate SSL/TLS certificates against the target hostname. The flaw allows remote, unauthenticated attackers to perform Man-in-the-Middle (MITM) attacks on the communication channel between the ZTNA portal and backend destination websites. No authentication is required; the attack is network-accessible. The vulnerability affects FortiOS 7.6.1–7.6.6 and FortiProxy 7.6.2–7.6.6. Patches are available: upgrade to FortiOS 7.6.7 or FortiProxy 7.6.7 and above.

Affected products

  • Fortinet FortiOS 7.6.1 through 7.6.6
  • Fortinet FortiProxy 7.6.2 through 7.6.6

Timeline

  • 2026-09-08: disclosed: Initial publication by Fortinet PSIRT

References

Related threats