
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-84392 is a NULL Pointer Dereference vulnerability (CWE-476) affecting Fortinet FortiOS, FortiProxy, and FortiPAM that allows an authenticated attacker to crash the httpsd daemon via crafted HTTP requests, resulting in a denial of service. It was disclosed on September 8, 2026, with Fortinet publishing advisory FG-IR-26-173. Affected versions include FortiOS 7.2 and 7.4 (all versions), FortiProxy 7.2, 7.4, and 7.6.0–7.6.6, and FortiPAM 1.0 through 1.9.0. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low) per NVD, and 2.5 (Low) per Fortinet's own scoring (Fortinet PSIRT).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and resides in the GUI component (httpsd daemon) of the affected Fortinet products. An authenticated attacker can send specially crafted HTTP requests to the management interface, triggering a null pointer dereference that causes the httpsd process to crash. Exploitation requires valid credentials (high privileges), making it a post-authentication issue with no known public proof-of-concept code at the time of disclosure. The vulnerability was discovered externally and reported by Vang3lis and Cyth from VARAS@IIE under responsible disclosure (Fortinet PSIRT).
Successful exploitation results in a denial of service by crashing the httpsd daemon, which handles the web-based management GUI of affected Fortinet products. This would disrupt administrative access to the device but does not result in unauthorized code execution, data exfiltration, or privilege escalation, as confidentiality and integrity impacts are rated None. The scope is limited to the affected device's management plane, with no evidence of lateral movement potential (Fortinet PSIRT).
No public proof-of-concept exploit code has been identified, and Fortinet confirms the vulnerability has not been exploited in the wild (Known Exploited: No). The EPSS score is approximately 0.0028 (0.28%), reflecting a low probability of exploitation in the near term. The NVD SSVC assessment classifies the vulnerability as non-automatable with partial technical impact. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Fortinet PSIRT).
Fortinet recommends upgrading to fixed versions as follows: FortiPAM 1.9.1 or above (for 1.9.0 users); FortiProxy 7.6.7 or above (for 7.6.0–7.6.6 users). Users running FortiOS 7.2 or 7.4, FortiProxy 7.2 or 7.4, or FortiPAM 1.0–1.8 should migrate to a fixed release, as no in-branch patch is available for those versions. FortiOS 7.6 and 8.0 are not affected. Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool can assist with planning the migration (Fortinet PSIRT).
Coverage of CVE-2026-84392 has been limited given its low severity rating. The vulnerability was noted in aggregator feeds such as VulDB and CVEFeed.io shortly after disclosure, and BeyondMachines included it in a broader roundup of Fortinet patches addressing authentication bypass and proxy flaws across the product line. No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking (Fortinet PSIRT).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."