Fortinet has identified a significant security flaw in its FortiOS and FortiProxy systems that could enable attackers to intercept communications. The vulnerability, found within the Agentless Zero Trust Network Access (ZTNA) portal, allows unauthorized individuals to perform man-in-the-middle attacks, potentially compromising sensitive data.
Vulnerability Details and Impact
The flaw, assigned CVE-2026-84393, was disclosed on September 8, 2026, with a CVSSv3 score of 7.3, indicating a high severity. The issue arises from improper certificate validation, a weakness categorized as CWE-295. This vulnerability can be exploited to intercept traffic between the ZTNA portal and its backend connections by presenting a fraudulent certificate.
Such a security gap can lead to attackers gaining access to sensitive information, including session details and application data, without using authentication credentials. The attack is unauthenticated, significantly increasing the risk for organizations that expose ZTNA portals to less secure network segments.
Affected Versions and Recommendations
The vulnerability affects specific versions of FortiOS and FortiProxy. FortiOS versions from 7.6.1 to 7.6.6 and FortiProxy versions from 7.6.2 to 7.6.6 are susceptible, while other versions remain unaffected. Fortinet advises users to upgrade to version 7.6.7 or later to mitigate the risk.
To assist with the upgrade process, Fortinet provides an official upgrade path tool, ensuring a smooth transition without disrupting existing ZTNA policies. Admins should prioritize this patching effort to minimize potential exposure to this security flaw.
Current Exploitation Status and Future Measures
As of now, there is no evidence of this vulnerability being exploited in real-world scenarios. Fortinet has confirmed that the flaw is not listed as a known exploited vulnerability. However, due to the nature of ZTNA portals, which are often exposed to the internet or semi-trusted zones, organizations should not delay in applying the necessary updates.
Ensuring that security systems are up-to-date is crucial in maintaining network integrity. Organizations using the affected ZTNA portals should act swiftly to upgrade to the recommended versions, thereby lessening the risk of potential breaches.
In conclusion, while there is no immediate evidence of exploitation, the potential for severe security breaches makes addressing this vulnerability a top priority for affected organizations. Staying proactive with updates and security patches remains an essential practice in safeguarding digital infrastructures.
