CVE-2026-23573
FortiOS vulnerability analysis and mitigation

Overview

CVE-2026-23573 is a reflected Cross-Site Scripting (XSS) vulnerability in the Agentless SSL-VPN component of Fortinet FortiOS, FortiProxy, and FortiPAM. It was disclosed on July 14, 2026, and affects FortiOS 7.6.0–7.6.6, FortiOS 7.4 and 7.2 all versions, FortiPAM 1.0 through 1.8.0, and FortiProxy 7.2.0–7.2.9 and 7.4.0–7.4.3. The vulnerability was reported by the UK's National Cyber Security Centre (NCSC) under responsible disclosure. It carries a CVSS v3.1 base score of 6.1 (Medium) (FortiGuard Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and specifically manifests as a reflected XSS in the Agentless SSL-VPN feature. An authenticated remote attacker can send crafted HTTP requests that cause malicious scripts to be reflected and executed in the context of a victim's browser session. Exploitation requires user interaction (e.g., a victim clicking a malicious link) and is only possible when the Agentless SSL-VPN feature is enabled; if this feature is not in use, there is no impact. A virtual patch (FG-VD-60129.0day) is available in FMWP database update 26.021 (FortiGuard Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary code or commands in the context of the victim's browser session, resulting in limited confidentiality and integrity impacts (both rated Low in CVSS). The vulnerability does not affect availability. Because the scope is changed (S:C in CVSS), the attacker's malicious script can affect resources beyond the vulnerable component, potentially enabling session hijacking, credential theft, or further social engineering attacks against users of the affected SSL-VPN portal (FortiGuard Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets running Fortinet FortiOS, FortiProxy, or FortiPAM with the Agentless SSL-VPN feature enabled, using network scanning or Shodan/Censys queries for Fortinet SSL-VPN portals.
  2. Authentication: Obtain valid credentials for the target system (e.g., through phishing or credential stuffing), as the vulnerability requires an authenticated session.
  3. Craft malicious request: Construct a crafted HTTP request targeting the Agentless SSL-VPN web interface that injects a malicious JavaScript payload into a parameter that is reflected unsanitized in the server's response.
  4. Deliver payload: Trick a victim user (e.g., an administrator) into clicking a specially crafted URL or link that triggers the reflected XSS payload in their browser.
  5. Execute code: The victim's browser executes the injected script in the context of the SSL-VPN portal, potentially enabling session token theft, credential harvesting, or further actions on behalf of the victim (FortiGuard Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests to the Agentless SSL-VPN portal containing URL-encoded JavaScript payloads (e.g., <script>, javascript:, onerror=, onload=) in query parameters or headers.
  • Logs: Web server or FortiOS access logs showing requests with XSS-characteristic strings (e.g., %3Cscript%3E, alert(, document.cookie) reflected in responses to the SSL-VPN endpoint.
  • Logs: Authentication logs showing successful logins followed immediately by unusual or repeated requests to SSL-VPN web interface endpoints from the same session.
  • Network: Outbound connections from victim browsers to unexpected external domains shortly after accessing the SSL-VPN portal, potentially indicating data exfiltration via XSS.
  • File System: No direct file system artifacts expected for a reflected XSS; however, monitor for any new or modified files in the FortiOS web root if post-exploitation activity is suspected (FortiGuard Advisory).

Mitigation and workarounds

Fortinet has released patched versions: FortiOS 7.6.7 or above, FortiPAM 1.8.1 or above, FortiProxy 7.4.4 or above, and FortiProxy 7.2.10 or above. Users on FortiOS 7.4, 7.2, or FortiPAM versions prior to 1.8 should migrate to a fixed release. As an immediate workaround, disabling the Agentless SSL-VPN feature eliminates the attack surface entirely, as Fortinet confirms there is no impact if this feature is not enabled. A virtual patch (FG-VD-60129.0day) is also available in FMWP database update 26.021 for organizations that cannot immediately upgrade. Use the Fortinet upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan the appropriate upgrade path (FortiGuard Advisory).

Community reactions

The vulnerability was part of a broader Fortinet patch release covering seven vulnerabilities across FortiOS, FortiProxy, FortiPAM, and FortiSandbox, which received coverage from several cybersecurity news outlets including CyberSecurityNews, GBHackers, and CyberPress. The UK's National Cyber Security Centre (NCSC) was credited with responsibly disclosing the vulnerability to Fortinet. No significant researcher controversy or notable social media debate has been observed around this specific CVE (FortiGuard Advisory).

Additional resources


SourceThis report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59837MEDIUM6.6
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-23573MEDIUM6.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-59839MEDIUM5.5
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-59840MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2025-62826MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management