
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84393 is an improper validation of certificate with host mismatch vulnerability (CWE-297) affecting Fortinet FortiOS and FortiProxy, which may allow an unauthenticated remote attacker to perform man-in-the-middle (MitM) attacks and achieve information disclosure. The vulnerability affects FortiOS versions 7.6.1 through 7.6.6 and FortiProxy versions 7.6.2 through 7.6.6, specifically within the Zero Trust Network Access (ZTNA) validation component. It was published on September 8, 2026, and is currently awaiting full NVD analysis. The CVSS v3.1 base score is 8.1 (High), with an ENISA-adjusted score of 7.3 (Medium) (Feedly, Fortinet PSIRT).
The root cause is classified as CWE-297 (Improper Validation of Certificate with Host Mismatch), meaning the affected products fail to properly verify that a TLS/SSL certificate presented during a connection matches the expected hostname. This flaw resides in the ZTNA (Zero Trust Network Access) validation logic of FortiOS and FortiProxy, where certificate host validation is insufficiently enforced. An unauthenticated network-based attacker with high attack complexity (e.g., positioned to intercept traffic) can exploit this to impersonate a trusted endpoint, enabling a man-in-the-middle attack. No public proof-of-concept code has been identified at this time (Feedly, Fortinet PSIRT, CyberSecurityNews).
Successful exploitation allows an attacker to intercept and potentially manipulate encrypted communications between clients and FortiOS/FortiProxy ZTNA endpoints, resulting in high confidentiality, integrity, and availability impact per the CVSS scoring. Sensitive data traversing ZTNA-protected connections — including credentials, session tokens, and business-critical information — could be exposed or tampered with. The scope is limited to the affected system (unchanged scope), but the ability to intercept ZTNA traffic could facilitate lateral movement within protected network segments (Feedly, ITSecurityNews).
As of the publication date, no active in-the-wild exploitation has been reported, and no proof-of-concept exploit code is publicly available. The EPSS score is 0.0, and the SSVC assessment indicates exploitation status as "none" and the vulnerability is not automatable due to high attack complexity requirements. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires the adversary to be in a network position capable of intercepting traffic, which limits opportunistic exploitation (Feedly).
Fortinet has issued an advisory under FG-IR-26-174; organizations should upgrade FortiOS to a version beyond 7.6.6 and FortiProxy to a version beyond 7.6.6 as patches become available. Until patching is possible, administrators should enforce strict network segmentation to limit the ability of attackers to achieve a man-in-the-middle position on ZTNA traffic paths, and monitor for anomalous certificate validation events in gateway logs. Enabling certificate pinning or additional mutual TLS (mTLS) controls where supported may reduce exposure (Fortinet PSIRT, Feedly).
Security news outlets including CyberSecurityNews, ITSecurityNews, and Cryptika covered the vulnerability shortly after disclosure, highlighting the MitM attack potential within ZTNA environments. Coverage emphasized the risk to organizations relying on FortiOS and FortiProxy for zero-trust access controls. No notable researcher commentary or significant social media discussion beyond initial news aggregation has been identified at this time (CyberSecurityNews, ITSecurityNews, Cryptika).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."