CVE-2026-84393: 
FortiOS Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-84393 is an improper certificate validation vulnerability (CWE-295) affecting the Agentless Zero Trust Network Access (ZTNA) portal in Fortinet FortiOS and FortiProxy. It allows a remote, unauthenticated attacker to perform a Man-in-the-Middle (MitM) attack on the communication channel between the ZTNA portal and the backend destination website. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; all other major version branches (7.2, 7.4, 8.0) are unaffected. The vulnerability was internally discovered and reported by John Headley of the Fortinet System Engineering team, with initial publication on September 8, 2026. Fortinet rates this High severity with a CVSSv3 score of 7.3, while NVD assigns a base score of 8.1 (High) (FortiGuard PSIRT, Feedly).

Detalhes técnicos

The root cause is improper validation of TLS/SSL certificates against the expected hostname (CWE-297 / CWE-295) within the FortiOS and FortiProxy Agentless ZTNA portal component. When the ZTNA portal proxies user traffic to a backend destination website, it fails to properly verify that the server certificate presented matches the intended host, enabling an attacker positioned on the network path to substitute a fraudulent certificate and intercept or manipulate the encrypted communication. Exploitation requires no authentication and no user interaction, but does require a network-adjacent or on-path position (high attack complexity), as the attacker must be able to intercept traffic between the ZTNA portal and the backend (FortiGuard PSIRT, IT Security News). No public proof-of-concept exploit code has been identified at this time.

Impacto

Successful exploitation allows an unauthenticated, remote attacker to conduct a Man-in-the-Middle attack on traffic flowing through the FortiOS/FortiProxy Agentless ZTNA portal, potentially exposing sensitive data transmitted between users and backend applications, including credentials, session tokens, and confidential business data. The NVD CVSS scoring reflects high confidentiality, integrity, and availability impact, indicating that an attacker could not only read but also modify or disrupt proxied communications. Organizations relying on ZTNA for secure application access may face significant data exposure and trust compromise if this vulnerability is exploited (FortiGuard PSIRT, Cybersecurity News).

Exploração

As of the publication date, there is no known in-the-wild exploitation of CVE-2026-84393, no public proof-of-concept code, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (FortiGuard PSIRT). The EPSS score is approximately 0.155%, indicating a low probability of exploitation in the near term. Exploitation requires a high-complexity network position (on-path/MitM capability), which limits opportunistic exploitation but does not preclude targeted attacks against organizations using FortiOS/FortiProxy ZTNA. No threat actor attribution has been reported (Feedly).

Etapas de exploração

  1. Reconnaissance: Identify target organizations using Fortinet FortiOS 7.6.1–7.6.6 or FortiProxy 7.6.2–7.6.6 with the Agentless ZTNA portal exposed, using network scanning or OSINT techniques.
  2. Gain on-path position: Position the attacker's system between the FortiOS/FortiProxy ZTNA portal and the backend destination website — for example, via ARP spoofing, BGP hijacking, DNS poisoning, or compromising a network device on the path.
  3. Intercept TLS handshake: When the ZTNA portal initiates a TLS connection to the backend, intercept the handshake and present a fraudulent certificate for the backend domain.
  4. Exploit certificate validation failure: Because the ZTNA portal does not properly validate the certificate's hostname against the expected backend host (CWE-297), it accepts the attacker's fraudulent certificate without error.
  5. Decrypt and relay traffic: Establish separate TLS sessions with both the ZTNA portal and the legitimate backend, decrypting, potentially modifying, and re-encrypting all traffic passing through — achieving full MitM access to user sessions, credentials, and application data (FortiGuard PSIRT, IT Security News).

Indicadores de compromisso

  • Network: Unexpected or anomalous TLS certificate presented to the FortiOS/FortiProxy ZTNA portal from a backend destination (certificate issuer, subject, or fingerprint mismatch compared to expected); unusual intermediate hosts appearing in network path traces between the ZTNA portal and backend servers.
  • Logs: FortiOS/FortiProxy SSL-VPN or ZTNA logs showing certificate validation warnings or errors for backend connections; unexpected IP addresses appearing as the backend server endpoint in proxy connection logs.
  • Network: Unusual latency or packet loss on ZTNA-proxied sessions that may indicate traffic interception and re-encryption by an on-path attacker.
  • File System / Configuration: No direct file-system IOCs are expected for this MitM-type vulnerability, as exploitation does not require code execution on the FortiOS device itself (FortiGuard PSIRT).

Mitigação e soluções alternativas

Fortinet has released patched versions addressing this vulnerability: upgrade FortiOS to 7.6.7 or above and FortiProxy to 7.6.7 or above. FortiOS 7.2, 7.4, and 8.0, as well as FortiProxy 7.2, 7.4, and 8.0, are not affected and require no action. Administrators should use Fortinet's official upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan their upgrade. No configuration-based workaround is documented; upgrading to the fixed version is the recommended and only confirmed remediation (FortiGuard PSIRT).

Reações da comunidade

Security news outlets including Cybersecurity News, IT Security News, and The Daily Tech Feed covered the vulnerability shortly after disclosure, highlighting the MitM risk to ZTNA deployments (Cybersecurity News, IT Security News). SecurityWeek and CyberHub Podcast included it in broader Fortinet patch roundups, noting it alongside more critical vulnerabilities patched in the same cycle (SecurityWeek, CyberHub Podcast). Community sentiment on platforms like Mastodon (VulDB) and dev.to noted the certificate validation flaw as a meaningful risk for enterprises relying on FortiOS ZTNA for secure access (dev.to). Overall reaction was measured, with no reports of active exploitation driving urgent alarm.

Recursos adicionais


Origem: Este relatório foi gerado usando IA

Relacionado FortiOS Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NãoSimSep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NãoSimAug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NãoSimAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NãoSimAug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NãoSimSep 08, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades