Illustrative image generated with AI
Fortinet Fixes Critical Authentication Flaws in FortiMonitorOnSight and Chrome Extension
Fortinet patched 10 flaws, including critical JWT auth bypass in FortiMonitorOnSight and Chrome extension proxy bug. Update FortiPAM and extension now.
Text generated by artificial intelligence, published without human review. AI transparency
Fortinet has released security updates for 10 vulnerabilities across its product portfolio, including two critical flaws that remote attackers can exploit without authentication.
The most urgent issues affect the FortiMonitorOnSight web portal and the Fortinet Privileged Access Agent extension for Google Chrome. The first can expose protected portal functions through forged or replayed JSON Web Tokens, while the second can let a malicious website turn a victim’s browser into a traffic proxy.
The company reported no evidence of exploitation in the wild. The vulnerabilities were disclosed as part of Fortinet’s Tuesday security release and reported on September 9, 2026.
Forged or replayed JWTs can defeat FortiMonitorOnSight authentication
Tracked as CVE-2026-84390, the FortiMonitorOnSight vulnerability carries a CVSS score of 9.6. Fortinet describes the underlying weakness as sensitive information exposed within the web portal’s source code.
A remote attacker does not need an existing account to exploit it. By submitting a forged JSON Web Token, or reusing a token that the application accepts, the attacker could bypass the portal’s authentication controls.
JWTs commonly carry signed claims identifying a user and defining what that user may access. Their security depends on correct signature verification, secure handling of signing material, and controls that prevent expired or previously used tokens from being accepted. In this case, the exposed information can support the creation or reuse of a token capable of passing the portal’s checks.
Successful exploitation could grant unauthorized access to protected portal functions. The available information does not specify whether attackers could obtain administrative privileges, alter monitoring configurations, or reach systems managed through the portal.
The affected and fixed FortiMonitorOnSight versions have not been disclosed. Administrators should therefore consult Fortinet’s product-specific PSIRT advisory before deciding whether a deployment is exposed.
Chrome extension flaw can proxy a victim’s browser traffic
The second critical vulnerability, CVE-2026-84388, affects the Fortinet Privileged Access Agent Chrome extension and has a CVSS score of 9.1.
It results from improper authentication between components involved in privileged-access operations. Exploitation begins when a user with the affected extension visits a website controlled by an attacker. The attacker can operate remotely and does not need to authenticate to Fortinet infrastructure beforehand.
A successful attack could cause the victim’s browser traffic to be proxied through an attacker-controlled path. That creates opportunities to observe traffic, interfere with requests, or manipulate data passing through the browser, depending on the surrounding security controls and encryption boundaries.
Remediation requires updates on both sides of the integration:
- Upgrade FortiPAM to version 1.9.1 or 1.8.4.
- Upgrade the Fortinet Privileged Access Agent Chrome extension to version 8.0.1.123 or later.
Updating only FortiPAM or only the browser extension is insufficient. Organizations should verify both versions rather than relying solely on centralized server patch status.
Managed Chrome environments can use browser-management inventory to identify outdated extension installations. Security teams should also check whether automatic extension updates are enabled and whether users can retain locally installed or unmanaged copies.
FortiSandbox and Agentless ZTNA flaws carry severe impact
Fortinet also fixed two significant vulnerabilities in FortiSandbox and the Agentless ZTNA portals provided by FortiOS and FortiProxy.
CVE-2026-26084 affects FortiSandbox and could expose sensitive information. It has a CVSS 3.1 score of 9.9, with the following vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
The vector indicates that exploitation is network-accessible, requires low attack complexity, and needs neither privileges nor user interaction. Its scope is changed, meaning exploitation can affect a security authority beyond the vulnerable component. The assessed impact includes limited confidentiality and integrity compromise but a high availability impact.
Although the vulnerability was presented among Fortinet’s high-severity fixes, its supplied CVSS score falls within the critical range under the standard CVSS 3.1 rating scale. Fixed and affected FortiSandbox versions have not been disclosed.
The other issue, CVE-2026-84393, affects the FortiOS and FortiProxy Agentless ZTNA portal. It could enable man-in-the-middle attacks and carries a CVSS score of 8.1:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
This flaw is remotely reachable and requires no privileges or user interaction, although exploitation has high complexity. A successful attack could have a high impact on confidentiality, integrity, and availability.
A man-in-the-middle condition involving a ZTNA portal is particularly relevant because the portal mediates access between users and protected applications. The available details do not establish which traffic or authentication steps can be intercepted, nor do they identify the conditions required to achieve the necessary network position.
No fixed-version information was provided for CVE-2026-26084 or CVE-2026-84393.
Six additional flaws span Fortinet’s security portfolio
The remaining medium- and low-severity vulnerabilities affect a broad set of enterprise products:
- FortiManager
- FortiAnalyzer
- FortiSandbox
- FortiSOAR
- FortiClient for Windows
- FortiSIEM
- FortiOS
- FortiProxy
- FortiPAM
Depending on the product and weakness, exploitation could bypass approval workflows, execute arbitrary code, inject broadcast messages, redirect users to attacker-selected websites, or produce denial-of-service conditions.
Other potential outcomes include process termination and crashes of the httpsd daemon. On Fortinet appliances, an httpsd failure may interrupt web-based management or another service dependent on that daemon, even if the underlying device remains operational.
Individual CVE identifiers, affected releases, and corrected versions for these additional flaws have not been disclosed in the available information. Administrators will need Fortinet’s PSIRT advisories to map each vulnerability to their installed product builds.
Defenders should prioritize exposed portals and paired updates
Internet-accessible FortiMonitorOnSight instances should receive immediate attention because CVE-2026-84390 is remotely exploitable without credentials. Until the relevant fixed releases are confirmed and installed, defenders should reduce unnecessary exposure through network access controls or other existing administrative restrictions.
FortiPAM customers should treat the server and Chrome extension upgrades as one change. Deployment teams should confirm that FortiPAM is running 1.9.1 or 1.8.4 and that every managed extension has reached 8.0.1.123 or later.
Monitoring priorities include:
- Authentication successes associated with unusual or previously observed JWTs.
- Repeated token use across different addresses, sessions, or user agents.
- Unexpected browser proxy configuration or unexplained changes in traffic paths.
- Suspicious connections occurring after visits to untrusted websites.
- Indicators of interception involving Agentless ZTNA sessions.
- Unusual access to sensitive FortiSandbox information.
httpsdcrashes, process termination, or unexplained service interruptions.
Fortinet has not reported active exploitation of any of the 10 vulnerabilities. No inclusion in CISA’s Known Exploited Vulnerabilities catalog, associated remediation deadline, or ransomware-use designation has been reported for these issues.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-26084Critical9.9A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
- CVE-2026-84393High8.1A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
