CVE-2026-84393: 
FortiOS Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-84393 is an improper certificate validation vulnerability (CWE-295) affecting the Agentless Zero Trust Network Access (ZTNA) portal in Fortinet FortiOS and FortiProxy. It allows a remote, unauthenticated attacker to perform a Man-in-the-Middle (MitM) attack on the communication channel between the ZTNA portal and the backend destination website. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; all other major version branches (7.2, 7.4, 8.0) are unaffected. The vulnerability was internally discovered and reported by John Headley of the Fortinet System Engineering team, with initial publication on September 8, 2026. Fortinet rates this High severity with a CVSSv3 score of 7.3, while NVD assigns a base score of 8.1 (High) (FortiGuard PSIRT, Feedly).

Dettagli tecnici

The root cause is improper validation of TLS/SSL certificates against the expected hostname (CWE-297 / CWE-295) within the FortiOS and FortiProxy Agentless ZTNA portal component. When the ZTNA portal proxies user traffic to a backend destination website, it fails to properly verify that the server certificate presented matches the intended host, enabling an attacker positioned on the network path to substitute a fraudulent certificate and intercept or manipulate the encrypted communication. Exploitation requires no authentication and no user interaction, but does require a network-adjacent or on-path position (high attack complexity), as the attacker must be able to intercept traffic between the ZTNA portal and the backend (FortiGuard PSIRT, IT Security News). No public proof-of-concept exploit code has been identified at this time.

Impatto

Successful exploitation allows an unauthenticated, remote attacker to conduct a Man-in-the-Middle attack on traffic flowing through the FortiOS/FortiProxy Agentless ZTNA portal, potentially exposing sensitive data transmitted between users and backend applications, including credentials, session tokens, and confidential business data. The NVD CVSS scoring reflects high confidentiality, integrity, and availability impact, indicating that an attacker could not only read but also modify or disrupt proxied communications. Organizations relying on ZTNA for secure application access may face significant data exposure and trust compromise if this vulnerability is exploited (FortiGuard PSIRT, Cybersecurity News).

Sfruttabilità

As of the publication date, there is no known in-the-wild exploitation of CVE-2026-84393, no public proof-of-concept code, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (FortiGuard PSIRT). The EPSS score is approximately 0.155%, indicating a low probability of exploitation in the near term. Exploitation requires a high-complexity network position (on-path/MitM capability), which limits opportunistic exploitation but does not preclude targeted attacks against organizations using FortiOS/FortiProxy ZTNA. No threat actor attribution has been reported (Feedly).

Passaggi di sfruttamento

  1. Reconnaissance: Identify target organizations using Fortinet FortiOS 7.6.1–7.6.6 or FortiProxy 7.6.2–7.6.6 with the Agentless ZTNA portal exposed, using network scanning or OSINT techniques.
  2. Gain on-path position: Position the attacker's system between the FortiOS/FortiProxy ZTNA portal and the backend destination website — for example, via ARP spoofing, BGP hijacking, DNS poisoning, or compromising a network device on the path.
  3. Intercept TLS handshake: When the ZTNA portal initiates a TLS connection to the backend, intercept the handshake and present a fraudulent certificate for the backend domain.
  4. Exploit certificate validation failure: Because the ZTNA portal does not properly validate the certificate's hostname against the expected backend host (CWE-297), it accepts the attacker's fraudulent certificate without error.
  5. Decrypt and relay traffic: Establish separate TLS sessions with both the ZTNA portal and the legitimate backend, decrypting, potentially modifying, and re-encrypting all traffic passing through — achieving full MitM access to user sessions, credentials, and application data (FortiGuard PSIRT, IT Security News).

Indicatori di compromesso

  • Network: Unexpected or anomalous TLS certificate presented to the FortiOS/FortiProxy ZTNA portal from a backend destination (certificate issuer, subject, or fingerprint mismatch compared to expected); unusual intermediate hosts appearing in network path traces between the ZTNA portal and backend servers.
  • Logs: FortiOS/FortiProxy SSL-VPN or ZTNA logs showing certificate validation warnings or errors for backend connections; unexpected IP addresses appearing as the backend server endpoint in proxy connection logs.
  • Network: Unusual latency or packet loss on ZTNA-proxied sessions that may indicate traffic interception and re-encryption by an on-path attacker.
  • File System / Configuration: No direct file-system IOCs are expected for this MitM-type vulnerability, as exploitation does not require code execution on the FortiOS device itself (FortiGuard PSIRT).

Mitigazione e soluzioni alternative

Fortinet has released patched versions addressing this vulnerability: upgrade FortiOS to 7.6.7 or above and FortiProxy to 7.6.7 or above. FortiOS 7.2, 7.4, and 8.0, as well as FortiProxy 7.2, 7.4, and 8.0, are not affected and require no action. Administrators should use Fortinet's official upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan their upgrade. No configuration-based workaround is documented; upgrading to the fixed version is the recommended and only confirmed remediation (FortiGuard PSIRT).

Reazioni della comunità

Security news outlets including Cybersecurity News, IT Security News, and The Daily Tech Feed covered the vulnerability shortly after disclosure, highlighting the MitM risk to ZTNA deployments (Cybersecurity News, IT Security News). SecurityWeek and CyberHub Podcast included it in broader Fortinet patch roundups, noting it alongside more critical vulnerabilities patched in the same cycle (SecurityWeek, CyberHub Podcast). Community sentiment on platforms like Mastodon (VulDB) and dev.to noted the certificate validation flaw as a meaningful risk for enterprises relying on FortiOS ZTNA for secure access (dev.to). Overall reaction was measured, with no reports of active exploitation driving urgent alarm.

Risorse aggiuntive


Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale

Imparentato FortiOS Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoSìSep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoSìAug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoSìAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoSìAug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoSìSep 08, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità