CVE-2026-84392: 
FortiOS Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-84392 is a NULL Pointer Dereference vulnerability (CWE-476) affecting Fortinet FortiOS, FortiProxy, and FortiPAM that allows an authenticated attacker to crash the httpsd daemon via crafted HTTP requests, resulting in a denial of service. It was disclosed on September 8, 2026, with Fortinet publishing advisory FG-IR-26-173. Affected versions include FortiOS 7.2 and 7.4 (all versions), FortiProxy 7.2, 7.4, and 7.6.0–7.6.6, and FortiPAM 1.0 through 1.9.0. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low) per NVD, and 2.5 (Low) per Fortinet's own scoring (Fortinet PSIRT).

Detalhes técnicos

The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and resides in the GUI component (httpsd daemon) of the affected Fortinet products. An authenticated attacker can send specially crafted HTTP requests to the management interface, triggering a null pointer dereference that causes the httpsd process to crash. Exploitation requires valid credentials (high privileges), making it a post-authentication issue with no known public proof-of-concept code at the time of disclosure. The vulnerability was discovered externally and reported by Vang3lis and Cyth from VARAS@IIE under responsible disclosure (Fortinet PSIRT).

Impacto

Successful exploitation results in a denial of service by crashing the httpsd daemon, which handles the web-based management GUI of affected Fortinet products. This would disrupt administrative access to the device but does not result in unauthorized code execution, data exfiltration, or privilege escalation, as confidentiality and integrity impacts are rated None. The scope is limited to the affected device's management plane, with no evidence of lateral movement potential (Fortinet PSIRT).

Exploração

No public proof-of-concept exploit code has been identified, and Fortinet confirms the vulnerability has not been exploited in the wild (Known Exploited: No). The EPSS score is approximately 0.0028 (0.28%), reflecting a low probability of exploitation in the near term. The NVD SSVC assessment classifies the vulnerability as non-automatable with partial technical impact. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Fortinet PSIRT).

Mitigação e soluções alternativas

Fortinet recommends upgrading to fixed versions as follows: FortiPAM 1.9.1 or above (for 1.9.0 users); FortiProxy 7.6.7 or above (for 7.6.0–7.6.6 users). Users running FortiOS 7.2 or 7.4, FortiProxy 7.2 or 7.4, or FortiPAM 1.0–1.8 should migrate to a fixed release, as no in-branch patch is available for those versions. FortiOS 7.6 and 8.0 are not affected. Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool can assist with planning the migration (Fortinet PSIRT).

Reações da comunidade

Coverage of CVE-2026-84392 has been limited given its low severity rating. The vulnerability was noted in aggregator feeds such as VulDB and CVEFeed.io shortly after disclosure, and BeyondMachines included it in a broader roundup of Fortinet patches addressing authentication bypass and proxy flaws across the product line. No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking (Fortinet PSIRT).

Recursos adicionais


Origem: Este relatório foi gerado usando IA

Relacionado FortiOS Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NãoSimSep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NãoSimAug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NãoSimAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NãoSimAug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NãoSimSep 08, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades