
PEACH
Un framework di isolamento del tenant
CVE-2026-84392 is a NULL Pointer Dereference vulnerability (CWE-476) affecting Fortinet FortiOS, FortiProxy, and FortiPAM that allows an authenticated attacker to crash the httpsd daemon via crafted HTTP requests, resulting in a denial of service. It was disclosed on September 8, 2026, with Fortinet publishing advisory FG-IR-26-173. Affected versions include FortiOS 7.2 and 7.4 (all versions), FortiProxy 7.2, 7.4, and 7.6.0–7.6.6, and FortiPAM 1.0 through 1.9.0. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low) per NVD, and 2.5 (Low) per Fortinet's own scoring (Fortinet PSIRT).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and resides in the GUI component (httpsd daemon) of the affected Fortinet products. An authenticated attacker can send specially crafted HTTP requests to the management interface, triggering a null pointer dereference that causes the httpsd process to crash. Exploitation requires valid credentials (high privileges), making it a post-authentication issue with no known public proof-of-concept code at the time of disclosure. The vulnerability was discovered externally and reported by Vang3lis and Cyth from VARAS@IIE under responsible disclosure (Fortinet PSIRT).
Successful exploitation results in a denial of service by crashing the httpsd daemon, which handles the web-based management GUI of affected Fortinet products. This would disrupt administrative access to the device but does not result in unauthorized code execution, data exfiltration, or privilege escalation, as confidentiality and integrity impacts are rated None. The scope is limited to the affected device's management plane, with no evidence of lateral movement potential (Fortinet PSIRT).
No public proof-of-concept exploit code has been identified, and Fortinet confirms the vulnerability has not been exploited in the wild (Known Exploited: No). The EPSS score is approximately 0.0028 (0.28%), reflecting a low probability of exploitation in the near term. The NVD SSVC assessment classifies the vulnerability as non-automatable with partial technical impact. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Fortinet PSIRT).
Fortinet recommends upgrading to fixed versions as follows: FortiPAM 1.9.1 or above (for 1.9.0 users); FortiProxy 7.6.7 or above (for 7.6.0–7.6.6 users). Users running FortiOS 7.2 or 7.4, FortiProxy 7.2 or 7.4, or FortiPAM 1.0–1.8 should migrate to a fixed release, as no in-branch patch is available for those versions. FortiOS 7.6 and 8.0 are not affected. Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool can assist with planning the migration (Fortinet PSIRT).
Coverage of CVE-2026-84392 has been limited given its low severity rating. The vulnerability was noted in aggregator feeds such as VulDB and CVEFeed.io shortly after disclosure, and BeyondMachines included it in a broader roundup of Fortinet patches addressing authentication bypass and proxy flaws across the product line. No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking (Fortinet PSIRT).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."