
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23573 is a reflected Cross-Site Scripting (XSS) vulnerability in the Agentless SSL-VPN component of Fortinet FortiOS, FortiProxy, and FortiPAM. It was disclosed on July 14, 2026, and affects FortiOS 7.6.0–7.6.6, FortiOS 7.4 and 7.2 all versions, FortiPAM 1.0 through 1.8.0, and FortiProxy 7.2.0–7.2.9 and 7.4.0–7.4.3. The vulnerability was reported by the UK's National Cyber Security Centre (NCSC) under responsible disclosure. It carries a CVSS v3.1 base score of 6.1 (Medium) (FortiGuard Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and specifically manifests as a reflected XSS in the Agentless SSL-VPN feature. An authenticated remote attacker can send crafted HTTP requests that cause malicious scripts to be reflected and executed in the context of a victim's browser session. Exploitation requires user interaction (e.g., a victim clicking a malicious link) and is only possible when the Agentless SSL-VPN feature is enabled; if this feature is not in use, there is no impact. A virtual patch (FG-VD-60129.0day) is available in FMWP database update 26.021 (FortiGuard Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary code or commands in the context of the victim's browser session, resulting in limited confidentiality and integrity impacts (both rated Low in CVSS). The vulnerability does not affect availability. Because the scope is changed (S:C in CVSS), the attacker's malicious script can affect resources beyond the vulnerable component, potentially enabling session hijacking, credential theft, or further social engineering attacks against users of the affected SSL-VPN portal (FortiGuard Advisory).
<script>, javascript:, onerror=, onload=) in query parameters or headers.%3Cscript%3E, alert(, document.cookie) reflected in responses to the SSL-VPN endpoint.Fortinet has released patched versions: FortiOS 7.6.7 or above, FortiPAM 1.8.1 or above, FortiProxy 7.4.4 or above, and FortiProxy 7.2.10 or above. Users on FortiOS 7.4, 7.2, or FortiPAM versions prior to 1.8 should migrate to a fixed release. As an immediate workaround, disabling the Agentless SSL-VPN feature eliminates the attack surface entirely, as Fortinet confirms there is no impact if this feature is not enabled. A virtual patch (FG-VD-60129.0day) is also available in FMWP database update 26.021 for organizations that cannot immediately upgrade. Use the Fortinet upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan the appropriate upgrade path (FortiGuard Advisory).
The vulnerability was part of a broader Fortinet patch release covering seven vulnerabilities across FortiOS, FortiProxy, FortiPAM, and FortiSandbox, which received coverage from several cybersecurity news outlets including CyberSecurityNews, GBHackers, and CyberPress. The UK's National Cyber Security Centre (NCSC) was credited with responsibly disclosing the vulnerability to Fortinet. No significant researcher controversy or notable social media debate has been observed around this specific CVE (FortiGuard Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."