VYPR
advisoryPublished Sep 8, 2026· 2 sources

Fortinet FortiOS and FortiProxy Vulnerability Enables Man-in-the-Middle Attacks

A critical vulnerability in Fortinet's Agentless ZTNA portal allows unauthenticated attackers to intercept sensitive traffic via man-in-the-middle attacks.

Fortinet has disclosed a critical vulnerability, tracked as CVE-2026-84393, affecting the Agentless Zero Trust Network Access (ZTNA) portal within its FortiOS and FortiProxy products. This flaw, stemming from improper certificate validation (CWE-295), enables unauthenticated remote attackers to conduct man-in-the-middle (MITM) attacks. The vulnerability carries a CVSSv3 score of 7.3, highlighting its significant security implications.

ZTNA portals are designed to provide secure, identity-verified access to internal applications without requiring a full VPN client. In this scenario, the improper certificate validation on the connection between the ZTNA portal and the backend destination website allows an attacker positioned on the network path to present a forged or mismatched certificate. This deception allows the attacker to intercept traffic, posing as a trusted intermediary to both the ZTNA portal and the target application, without raising any alarms.

The primary impact of a successful exploitation is information disclosure. Attackers can potentially gain access to sensitive data traversing the compromised channel, including session details, authentication tokens, or application content. The unauthenticated nature of the attack vector is particularly concerning, as it lowers the barrier to entry for malicious actors, requiring no prior access or valid credentials to initiate the interception.

The vulnerability specifically impacts FortiOS versions 7.6.1 through 7.6.6 and FortiProxy versions 7.6.2 through 7.6.6. Fortinet has confirmed that other branches, including FortiOS and FortiProxy 8.0, 7.4, and 7.2, are not affected by this particular flaw.

Fortinet recommends that administrators running the affected versions of FortiOS and FortiProxy upgrade to version 7.6.7 or later as soon as possible. The vendor also provides an upgrade path tool to assist customers in planning and executing the migration smoothly, ensuring minimal disruption to existing ZTNA policies and operations.

As of the disclosure, there is no evidence to suggest that CVE-2026-84393 has been actively exploited in the wild. Fortinet has also confirmed that the vulnerability is not currently listed on any known exploited vulnerabilities (KEV) lists.

Given that ZTNA portals are often exposed to the internet or semi-trusted network segments, organizations utilizing the affected Fortinet products should prioritize applying the available patches. Failing to do so leaves them susceptible to unauthenticated MITM attacks, significantly increasing their exposure to sensitive data breaches until remediation is complete.

This vulnerability underscores the ongoing importance of robust certificate validation mechanisms, especially in perimeter-facing security solutions like ZTNA gateways. Organizations must remain vigilant in patching their infrastructure promptly to mitigate risks associated with such critical flaws.

This advisory updates the initial report by providing a CVSSv3 score of 7.3 for the vulnerability. It also clarifies that the flaw affects both FortiOS and FortiProxy Agentless ZTNA portals, and specifically targets the communication channel between the ZTNA portal and backend destination websites.

Synthesized by Vypr AI