CVE-2026-84393
FortiOS vulnerability analysis and mitigation

Overview

CVE-2026-84393 is an improper validation of certificate with host mismatch vulnerability (CWE-297) affecting Fortinet FortiOS and FortiProxy, which may allow an unauthenticated remote attacker to perform man-in-the-middle (MitM) attacks and achieve information disclosure. The vulnerability affects FortiOS versions 7.6.1 through 7.6.6 and FortiProxy versions 7.6.2 through 7.6.6, specifically within the Zero Trust Network Access (ZTNA) validation component. It was published on September 8, 2026, and is currently awaiting full NVD analysis. The CVSS v3.1 base score is 8.1 (High), with an ENISA-adjusted score of 7.3 (Medium) (Feedly, Fortinet PSIRT).

Technical details

The root cause is classified as CWE-297 (Improper Validation of Certificate with Host Mismatch), meaning the affected products fail to properly verify that a TLS/SSL certificate presented during a connection matches the expected hostname. This flaw resides in the ZTNA (Zero Trust Network Access) validation logic of FortiOS and FortiProxy, where certificate host validation is insufficiently enforced. An unauthenticated network-based attacker with high attack complexity (e.g., positioned to intercept traffic) can exploit this to impersonate a trusted endpoint, enabling a man-in-the-middle attack. No public proof-of-concept code has been identified at this time (Feedly, Fortinet PSIRT, CyberSecurityNews).

Impact

Successful exploitation allows an attacker to intercept and potentially manipulate encrypted communications between clients and FortiOS/FortiProxy ZTNA endpoints, resulting in high confidentiality, integrity, and availability impact per the CVSS scoring. Sensitive data traversing ZTNA-protected connections — including credentials, session tokens, and business-critical information — could be exposed or tampered with. The scope is limited to the affected system (unchanged scope), but the ability to intercept ZTNA traffic could facilitate lateral movement within protected network segments (Feedly, ITSecurityNews).

Exploitability

As of the publication date, no active in-the-wild exploitation has been reported, and no proof-of-concept exploit code is publicly available. The EPSS score is 0.0, and the SSVC assessment indicates exploitation status as "none" and the vulnerability is not automatable due to high attack complexity requirements. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires the adversary to be in a network position capable of intercepting traffic, which limits opportunistic exploitation (Feedly).

Exploitation steps

  1. Reconnaissance: Identify FortiOS (7.6.1–7.6.6) or FortiProxy (7.6.2–7.6.6) deployments with ZTNA enabled using network scanning tools such as Shodan, Censys, or Nmap targeting known Fortinet management and ZTNA gateway ports.
  2. Network Positioning: Achieve a man-in-the-middle position on the network path between a ZTNA client and the FortiOS/FortiProxy gateway — for example, via ARP spoofing, DNS poisoning, or BGP hijacking on a shared network segment.
  3. Certificate Substitution: Present a fraudulent TLS certificate with a mismatched hostname to the ZTNA client or gateway. Due to the improper host validation, the affected product fails to reject the mismatched certificate.
  4. Traffic Interception/Manipulation: With the MitM position established and the certificate accepted, intercept, decrypt, and optionally modify traffic flowing through the ZTNA tunnel, capturing credentials, session tokens, or sensitive application data.
  5. Lateral Movement (Optional): Use captured credentials or session tokens to authenticate to internal resources protected by the ZTNA policy, enabling further access within the network (CyberSecurityNews, Feedly).

Indicators of compromise

  • Network: Unexpected TLS certificate hostname mismatches observed in ZTNA gateway logs; unusual ARP or DNS activity on network segments hosting FortiOS/FortiProxy gateways; TLS handshakes with certificates issued by untrusted or unexpected certificate authorities.
  • Logs: FortiOS/FortiProxy logs showing certificate validation warnings or errors for ZTNA sessions; repeated failed or anomalous ZTNA authentication attempts from unexpected source IPs.
  • Process/Session: ZTNA sessions established with certificates whose Common Name (CN) or Subject Alternative Name (SAN) does not match the expected gateway hostname; sessions originating from IP addresses inconsistent with known client populations.

Mitigation and workarounds

Fortinet has issued an advisory under FG-IR-26-174; organizations should upgrade FortiOS to a version beyond 7.6.6 and FortiProxy to a version beyond 7.6.6 as patches become available. Until patching is possible, administrators should enforce strict network segmentation to limit the ability of attackers to achieve a man-in-the-middle position on ZTNA traffic paths, and monitor for anomalous certificate validation events in gateway logs. Enabling certificate pinning or additional mutual TLS (mTLS) controls where supported may reduce exposure (Fortinet PSIRT, Feedly).

Community reactions

Security news outlets including CyberSecurityNews, ITSecurityNews, and Cryptika covered the vulnerability shortly after disclosure, highlighting the MitM attack potential within ZTNA environments. Coverage emphasized the risk to organizations relying on FortiOS and FortiProxy for zero-trust access controls. No notable researcher commentary or significant social media discussion beyond initial news aggregation has been identified at this time (CyberSecurityNews, ITSecurityNews, Cryptika).

Additional resources


SourceThis report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesSep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management