CVE-2026-84393: 
FortiOS 취약성 분석 및 완화

개요

CVE-2026-84393 is an improper certificate validation vulnerability (CWE-295) affecting the Agentless Zero Trust Network Access (ZTNA) portal in Fortinet FortiOS and FortiProxy. It allows a remote, unauthenticated attacker to perform a Man-in-the-Middle (MitM) attack on the communication channel between the ZTNA portal and the backend destination website. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; all other major version branches (7.2, 7.4, 8.0) are unaffected. The vulnerability was internally discovered and reported by John Headley of the Fortinet System Engineering team, with initial publication on September 8, 2026. Fortinet rates this High severity with a CVSSv3 score of 7.3, while NVD assigns a base score of 8.1 (High) (FortiGuard PSIRT, Feedly).

기술적 세부 사항

The root cause is improper validation of TLS/SSL certificates against the expected hostname (CWE-297 / CWE-295) within the FortiOS and FortiProxy Agentless ZTNA portal component. When the ZTNA portal proxies user traffic to a backend destination website, it fails to properly verify that the server certificate presented matches the intended host, enabling an attacker positioned on the network path to substitute a fraudulent certificate and intercept or manipulate the encrypted communication. Exploitation requires no authentication and no user interaction, but does require a network-adjacent or on-path position (high attack complexity), as the attacker must be able to intercept traffic between the ZTNA portal and the backend (FortiGuard PSIRT, IT Security News). No public proof-of-concept exploit code has been identified at this time.

영향

Successful exploitation allows an unauthenticated, remote attacker to conduct a Man-in-the-Middle attack on traffic flowing through the FortiOS/FortiProxy Agentless ZTNA portal, potentially exposing sensitive data transmitted between users and backend applications, including credentials, session tokens, and confidential business data. The NVD CVSS scoring reflects high confidentiality, integrity, and availability impact, indicating that an attacker could not only read but also modify or disrupt proxied communications. Organizations relying on ZTNA for secure application access may face significant data exposure and trust compromise if this vulnerability is exploited (FortiGuard PSIRT, Cybersecurity News).

악용 가능성

As of the publication date, there is no known in-the-wild exploitation of CVE-2026-84393, no public proof-of-concept code, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (FortiGuard PSIRT). The EPSS score is approximately 0.155%, indicating a low probability of exploitation in the near term. Exploitation requires a high-complexity network position (on-path/MitM capability), which limits opportunistic exploitation but does not preclude targeted attacks against organizations using FortiOS/FortiProxy ZTNA. No threat actor attribution has been reported (Feedly).

착취 단계

  1. Reconnaissance: Identify target organizations using Fortinet FortiOS 7.6.1–7.6.6 or FortiProxy 7.6.2–7.6.6 with the Agentless ZTNA portal exposed, using network scanning or OSINT techniques.
  2. Gain on-path position: Position the attacker's system between the FortiOS/FortiProxy ZTNA portal and the backend destination website — for example, via ARP spoofing, BGP hijacking, DNS poisoning, or compromising a network device on the path.
  3. Intercept TLS handshake: When the ZTNA portal initiates a TLS connection to the backend, intercept the handshake and present a fraudulent certificate for the backend domain.
  4. Exploit certificate validation failure: Because the ZTNA portal does not properly validate the certificate's hostname against the expected backend host (CWE-297), it accepts the attacker's fraudulent certificate without error.
  5. Decrypt and relay traffic: Establish separate TLS sessions with both the ZTNA portal and the legitimate backend, decrypting, potentially modifying, and re-encrypting all traffic passing through — achieving full MitM access to user sessions, credentials, and application data (FortiGuard PSIRT, IT Security News).

타협의 징후

  • Network: Unexpected or anomalous TLS certificate presented to the FortiOS/FortiProxy ZTNA portal from a backend destination (certificate issuer, subject, or fingerprint mismatch compared to expected); unusual intermediate hosts appearing in network path traces between the ZTNA portal and backend servers.
  • Logs: FortiOS/FortiProxy SSL-VPN or ZTNA logs showing certificate validation warnings or errors for backend connections; unexpected IP addresses appearing as the backend server endpoint in proxy connection logs.
  • Network: Unusual latency or packet loss on ZTNA-proxied sessions that may indicate traffic interception and re-encryption by an on-path attacker.
  • File System / Configuration: No direct file-system IOCs are expected for this MitM-type vulnerability, as exploitation does not require code execution on the FortiOS device itself (FortiGuard PSIRT).

완화 및 해결 방법

Fortinet has released patched versions addressing this vulnerability: upgrade FortiOS to 7.6.7 or above and FortiProxy to 7.6.7 or above. FortiOS 7.2, 7.4, and 8.0, as well as FortiProxy 7.2, 7.4, and 8.0, are not affected and require no action. Administrators should use Fortinet's official upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan their upgrade. No configuration-based workaround is documented; upgrading to the fixed version is the recommended and only confirmed remediation (FortiGuard PSIRT).

커뮤니티 반응

Security news outlets including Cybersecurity News, IT Security News, and The Daily Tech Feed covered the vulnerability shortly after disclosure, highlighting the MitM risk to ZTNA deployments (Cybersecurity News, IT Security News). SecurityWeek and CyberHub Podcast included it in broader Fortinet patch roundups, noting it alongside more critical vulnerabilities patched in the same cycle (SecurityWeek, CyberHub Podcast). Community sentiment on platforms like Mastodon (VulDB) and dev.to noted the certificate validation flaw as a meaningful risk for enterprises relying on FortiOS ZTNA for secure access (dev.to). Overall reaction was measured, with no reports of active exploitation driving urgent alarm.

추가 자료


근원: 이 보고서는 AI를 사용하여 생성되었습니다.

관련 FortiOS 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
아니요예Sep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
아니요예Aug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
아니요예Aug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
아니요예Aug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
아니요예Sep 08, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자