CVE-2026-84393:
FortiOS 취약성 분석 및 완화
개요
CVE-2026-84393 is an improper certificate validation vulnerability (CWE-295) affecting the Agentless Zero Trust Network Access (ZTNA) portal in Fortinet FortiOS and FortiProxy. It allows a remote, unauthenticated attacker to perform a Man-in-the-Middle (MitM) attack on the communication channel between the ZTNA portal and the backend destination website. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; all other major version branches (7.2, 7.4, 8.0) are unaffected. The vulnerability was internally discovered and reported by John Headley of the Fortinet System Engineering team, with initial publication on September 8, 2026. Fortinet rates this High severity with a CVSSv3 score of 7.3, while NVD assigns a base score of 8.1 (High) (FortiGuard PSIRT, Feedly).
기술적 세부 사항
The root cause is improper validation of TLS/SSL certificates against the expected hostname (CWE-297 / CWE-295) within the FortiOS and FortiProxy Agentless ZTNA portal component. When the ZTNA portal proxies user traffic to a backend destination website, it fails to properly verify that the server certificate presented matches the intended host, enabling an attacker positioned on the network path to substitute a fraudulent certificate and intercept or manipulate the encrypted communication. Exploitation requires no authentication and no user interaction, but does require a network-adjacent or on-path position (high attack complexity), as the attacker must be able to intercept traffic between the ZTNA portal and the backend (FortiGuard PSIRT, IT Security News). No public proof-of-concept exploit code has been identified at this time.
영향
Successful exploitation allows an unauthenticated, remote attacker to conduct a Man-in-the-Middle attack on traffic flowing through the FortiOS/FortiProxy Agentless ZTNA portal, potentially exposing sensitive data transmitted between users and backend applications, including credentials, session tokens, and confidential business data. The NVD CVSS scoring reflects high confidentiality, integrity, and availability impact, indicating that an attacker could not only read but also modify or disrupt proxied communications. Organizations relying on ZTNA for secure application access may face significant data exposure and trust compromise if this vulnerability is exploited (FortiGuard PSIRT, Cybersecurity News).
악용 가능성
As of the publication date, there is no known in-the-wild exploitation of CVE-2026-84393, no public proof-of-concept code, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (FortiGuard PSIRT). The EPSS score is approximately 0.155%, indicating a low probability of exploitation in the near term. Exploitation requires a high-complexity network position (on-path/MitM capability), which limits opportunistic exploitation but does not preclude targeted attacks against organizations using FortiOS/FortiProxy ZTNA. No threat actor attribution has been reported (Feedly).
착취 단계
- Reconnaissance: Identify target organizations using Fortinet FortiOS 7.6.1–7.6.6 or FortiProxy 7.6.2–7.6.6 with the Agentless ZTNA portal exposed, using network scanning or OSINT techniques.
- Gain on-path position: Position the attacker's system between the FortiOS/FortiProxy ZTNA portal and the backend destination website — for example, via ARP spoofing, BGP hijacking, DNS poisoning, or compromising a network device on the path.
- Intercept TLS handshake: When the ZTNA portal initiates a TLS connection to the backend, intercept the handshake and present a fraudulent certificate for the backend domain.
- Exploit certificate validation failure: Because the ZTNA portal does not properly validate the certificate's hostname against the expected backend host (CWE-297), it accepts the attacker's fraudulent certificate without error.
- Decrypt and relay traffic: Establish separate TLS sessions with both the ZTNA portal and the legitimate backend, decrypting, potentially modifying, and re-encrypting all traffic passing through — achieving full MitM access to user sessions, credentials, and application data (FortiGuard PSIRT, IT Security News).
타협의 징후
- Network: Unexpected or anomalous TLS certificate presented to the FortiOS/FortiProxy ZTNA portal from a backend destination (certificate issuer, subject, or fingerprint mismatch compared to expected); unusual intermediate hosts appearing in network path traces between the ZTNA portal and backend servers.
- Logs: FortiOS/FortiProxy SSL-VPN or ZTNA logs showing certificate validation warnings or errors for backend connections; unexpected IP addresses appearing as the backend server endpoint in proxy connection logs.
- Network: Unusual latency or packet loss on ZTNA-proxied sessions that may indicate traffic interception and re-encryption by an on-path attacker.
- File System / Configuration: No direct file-system IOCs are expected for this MitM-type vulnerability, as exploitation does not require code execution on the FortiOS device itself (FortiGuard PSIRT).
완화 및 해결 방법
Fortinet has released patched versions addressing this vulnerability: upgrade FortiOS to 7.6.7 or above and FortiProxy to 7.6.7 or above. FortiOS 7.2, 7.4, and 8.0, as well as FortiProxy 7.2, 7.4, and 8.0, are not affected and require no action. Administrators should use Fortinet's official upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan their upgrade. No configuration-based workaround is documented; upgrading to the fixed version is the recommended and only confirmed remediation (FortiGuard PSIRT).
커뮤니티 반응
Security news outlets including Cybersecurity News, IT Security News, and The Daily Tech Feed covered the vulnerability shortly after disclosure, highlighting the MitM risk to ZTNA deployments (Cybersecurity News, IT Security News). SecurityWeek and CyberHub Podcast included it in broader Fortinet patch roundups, noting it alongside more critical vulnerabilities patched in the same cycle (SecurityWeek, CyberHub Podcast). Community sentiment on platforms like Mastodon (VulDB) and dev.to noted the certificate validation flaw as a meaningful risk for enterprises relying on FortiOS ZTNA for secure access (dev.to). Overall reaction was measured, with no reports of active exploitation driving urgent alarm.
추가 자료
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 FortiOS 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."