Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Security Flaws in Key Products

Fortinet Addresses Critical Security Flaws in Key Products

Posted on September 9, 2026 By CWS

Fortinet has taken significant steps to bolster the security of its products by releasing patches for ten vulnerabilities, two of which are deemed critical. This development, announced on Tuesday, underscores the company’s ongoing commitment to safeguarding its users against potential cyber threats.

Critical Vulnerabilities in FortiMonitorOnSight and Chrome Extension

The first major vulnerability, identified as CVE-2026-84390 with a severity score of 9.6, involves the FortiMonitorOnSight web portal. This flaw arises from the inclusion of sensitive information in the source code, posing a risk of unauthorized access. An attacker, without any authentication, could exploit this weakness to bypass security protocols using a forged or reused JSON Web Token (JWT).

Another critical issue, labeled CVE-2026-84388 and scoring 9.1, affects the Fortinet Privileged Access Agent Chrome extension. This improper authentication vulnerability allows attackers to redirect a user’s browser traffic, provided the user visits a malicious site. Fortinet has advised users to update FortiPAM to version 1.9.1 or 1.8.4 and ensure the Chrome extension is upgraded to version 8.0.1.123 or later to mitigate these risks.

Additional High-Severity Vulnerabilities Addressed

Beyond the critical flaws, Fortinet has also resolved several high-severity vulnerabilities. Notably, a security flaw in FortiSandbox, tracked as CVE-2026-26084, could lead to unauthorized access to sensitive information. Additionally, weaknesses in FortiOS and the FortiProxy Agentless ZTNA portal, identified as CVE-2026-84393, might enable attackers to execute man-in-the-middle (MitM) attacks.

These vulnerabilities highlight the necessity for users to maintain updated systems to protect against potential exploits. Fortinet emphasizes the importance of implementing these patches to thwart possible security breaches.

Resolving Medium and Low-Severity Issues

In addition to addressing critical and high-severity vulnerabilities, Fortinet’s latest update includes fixes for medium and low-severity issues across a range of products, including FortiManager, FortiAnalyzer, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy, and FortiPAM. These patches aim to prevent exploits that could bypass approval workflows, cause denial-of-service (DoS) conditions, execute arbitrary code, or lead to unauthorized actions like message injection and process termination.

While there have been no reports of these vulnerabilities being actively exploited, Fortinet encourages users to remain vigilant and promptly apply the latest security updates. Additional details can be accessed via the company’s PSIRT advisories page.

For more information on similar security updates, see related articles on patch releases by Schneider Electric, Siemens, Ivanti, and recent updates from Chrome and Microsoft.

Security Week News Tags:Chrome extension, CVE-2026-84388, CVE-2026-84390, Cybersecurity, FortiManager, FortiMonitorOnSight, Fortinet, Fortinet Privileged Access Agent, FortiOS, FortiPAM, FortiProxy, FortiSandbox, security patches, Vulnerabilities

Post navigation

Previous Post: AI User Accounts Targeted by Infostealer Logs
Next Post: AI-Powered Cyberattack Exploits PaperCut Vulnerabilities

Related Posts

Police in Brazil Arrest a Suspect Over 0M Banking Hack Police in Brazil Arrest a Suspect Over $100M Banking Hack Security Week News
Cyber Espionage Group Targets 37 Nations’ Infrastructure Cyber Espionage Group Targets 37 Nations’ Infrastructure Security Week News
Daemon Tools Supply Chain Attack Targets Global Institutions Daemon Tools Supply Chain Attack Targets Global Institutions Security Week News
JetStream Debuts with M to Enhance AI Security JetStream Debuts with $34M to Enhance AI Security Security Week News
Akira Ransomware Group Made 4 Million in Ransom Proceeds Akira Ransomware Group Made $244 Million in Ransom Proceeds Security Week News
Exploited Vulnerability Impacts Over 80,000 Roundcube Servers Exploited Vulnerability Impacts Over 80,000 Roundcube Servers Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Exploits PaperCut Vulnerabilities
  • Fortinet Addresses Critical Security Flaws in Key Products
  • AI User Accounts Targeted by Infostealer Logs
  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Exploits PaperCut Vulnerabilities
  • Fortinet Addresses Critical Security Flaws in Key Products
  • AI User Accounts Targeted by Infostealer Logs
  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark