CVE-2026-84392: 
FortiOS Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-84392 is a NULL Pointer Dereference vulnerability (CWE-476) affecting Fortinet FortiOS, FortiProxy, and FortiPAM that allows an authenticated attacker to crash the httpsd daemon via crafted HTTP requests, resulting in a denial of service. It was disclosed on September 8, 2026, with Fortinet publishing advisory FG-IR-26-173. Affected versions include FortiOS 7.2 and 7.4 (all versions), FortiProxy 7.2, 7.4, and 7.6.0–7.6.6, and FortiPAM 1.0 through 1.9.0. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low) per NVD, and 2.5 (Low) per Fortinet's own scoring (Fortinet PSIRT).

Dettagli tecnici

The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and resides in the GUI component (httpsd daemon) of the affected Fortinet products. An authenticated attacker can send specially crafted HTTP requests to the management interface, triggering a null pointer dereference that causes the httpsd process to crash. Exploitation requires valid credentials (high privileges), making it a post-authentication issue with no known public proof-of-concept code at the time of disclosure. The vulnerability was discovered externally and reported by Vang3lis and Cyth from VARAS@IIE under responsible disclosure (Fortinet PSIRT).

Impatto

Successful exploitation results in a denial of service by crashing the httpsd daemon, which handles the web-based management GUI of affected Fortinet products. This would disrupt administrative access to the device but does not result in unauthorized code execution, data exfiltration, or privilege escalation, as confidentiality and integrity impacts are rated None. The scope is limited to the affected device's management plane, with no evidence of lateral movement potential (Fortinet PSIRT).

Sfruttabilità

No public proof-of-concept exploit code has been identified, and Fortinet confirms the vulnerability has not been exploited in the wild (Known Exploited: No). The EPSS score is approximately 0.0028 (0.28%), reflecting a low probability of exploitation in the near term. The NVD SSVC assessment classifies the vulnerability as non-automatable with partial technical impact. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Fortinet PSIRT).

Mitigazione e soluzioni alternative

Fortinet recommends upgrading to fixed versions as follows: FortiPAM 1.9.1 or above (for 1.9.0 users); FortiProxy 7.6.7 or above (for 7.6.0–7.6.6 users). Users running FortiOS 7.2 or 7.4, FortiProxy 7.2 or 7.4, or FortiPAM 1.0–1.8 should migrate to a fixed release, as no in-branch patch is available for those versions. FortiOS 7.6 and 8.0 are not affected. Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool can assist with planning the migration (Fortinet PSIRT).

Reazioni della comunità

Coverage of CVE-2026-84392 has been limited given its low severity rating. The vulnerability was noted in aggregator feeds such as VulDB and CVEFeed.io shortly after disclosure, and BeyondMachines included it in a broader roundup of Fortinet patches addressing authentication bypass and proxy flaws across the product line. No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking (Fortinet PSIRT).

Risorse aggiuntive


Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale

Imparentato FortiOS Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoSìSep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoSìAug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoSìAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoSìAug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoSìSep 08, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità