Fortinet has taken significant steps to bolster the security of its products by releasing patches for ten vulnerabilities, two of which are deemed critical. This development, announced on Tuesday, underscores the company’s ongoing commitment to safeguarding its users against potential cyber threats.
Critical Vulnerabilities in FortiMonitorOnSight and Chrome Extension
The first major vulnerability, identified as CVE-2026-84390 with a severity score of 9.6, involves the FortiMonitorOnSight web portal. This flaw arises from the inclusion of sensitive information in the source code, posing a risk of unauthorized access. An attacker, without any authentication, could exploit this weakness to bypass security protocols using a forged or reused JSON Web Token (JWT).
Another critical issue, labeled CVE-2026-84388 and scoring 9.1, affects the Fortinet Privileged Access Agent Chrome extension. This improper authentication vulnerability allows attackers to redirect a user’s browser traffic, provided the user visits a malicious site. Fortinet has advised users to update FortiPAM to version 1.9.1 or 1.8.4 and ensure the Chrome extension is upgraded to version 8.0.1.123 or later to mitigate these risks.
Additional High-Severity Vulnerabilities Addressed
Beyond the critical flaws, Fortinet has also resolved several high-severity vulnerabilities. Notably, a security flaw in FortiSandbox, tracked as CVE-2026-26084, could lead to unauthorized access to sensitive information. Additionally, weaknesses in FortiOS and the FortiProxy Agentless ZTNA portal, identified as CVE-2026-84393, might enable attackers to execute man-in-the-middle (MitM) attacks.
These vulnerabilities highlight the necessity for users to maintain updated systems to protect against potential exploits. Fortinet emphasizes the importance of implementing these patches to thwart possible security breaches.
Resolving Medium and Low-Severity Issues
In addition to addressing critical and high-severity vulnerabilities, Fortinet’s latest update includes fixes for medium and low-severity issues across a range of products, including FortiManager, FortiAnalyzer, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy, and FortiPAM. These patches aim to prevent exploits that could bypass approval workflows, cause denial-of-service (DoS) conditions, execute arbitrary code, or lead to unauthorized actions like message injection and process termination.
While there have been no reports of these vulnerabilities being actively exploited, Fortinet encourages users to remain vigilant and promptly apply the latest security updates. Additional details can be accessed via the company’s PSIRT advisories page.
For more information on similar security updates, see related articles on patch releases by Schneider Electric, Siemens, Ivanti, and recent updates from Chrome and Microsoft.
