Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
September 8, 2026
Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, including 2 zero-days
September 8, 2026
Phishing Powers 80% of Attacks on US Companies: SOCs Can Detect It Early
September 8, 2026
Home/CyberSecurity News/FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
CyberSecurity News

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Key Takeaways A high-severity vulnerability (CVE-2026-84393) has been discovered in FortiOS and FortiProxy Agentless ZTNA portals. The flaw allows an unauthenticated remote attacker to conduct a...

Emy Elsamnoudy
Emy Elsamnoudy
September 8, 2026 3 Min Read
3 0

Key Takeaways

  • A high-severity vulnerability (CVE-2026-84393) has been discovered in FortiOS and FortiProxy Agentless ZTNA portals.
  • The flaw allows an unauthenticated remote attacker to conduct a Man-in-the-Middle (MitM) attack by exploiting improper certificate validation.
  • Affected versions include FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6.
  • A fix is available; administrators should upgrade to version 7.6.7 or later for both products.

Fortinet Discloses High-Severity ZTNA Vulnerability Enabling Man-in-the-Middle Attacks

Fortinet has issued a critical warning regarding a high-severity flaw impacting the Agentless Zero Trust Network Access (ZTNA) portal within its FortiOS and FortiProxy products. This vulnerability, if exploited, could allow an unauthenticated remote attacker to intercept and potentially manipulate traffic flowing between the ZTNA portal and backend destination websites.

Table Of Content

  • Key Takeaways
  • Fortinet Discloses High-Severity ZTNA Vulnerability Enabling Man-in-the-Middle Attacks
  • Technical Details of the Vulnerability
  • Affected Versions and Remediation
  • What You Should Do

Technical Details of the Vulnerability

Designated CVE-2026-84393 and outlined in advisory FG-IR-26-174, the issue was publicly disclosed on September 8, 2026. It carries a CVSSv3 score of 7.3, reflecting its significant potential impact.

The core of the problem lies in an improper certificate validation mechanism, categorized under CWE-295, within the Agentless ZTNA portal. ZTNA portals are engineered to establish secure, verified connections between end-users and internal applications, circumventing the need for a full Virtual Private Network (VPN) client. However, when the backend connection fails to rigorously enforce certificate validation, an attacker positioned on the network path can introduce a forged or mismatched certificate, going undetected by the system.

This oversight creates a classic Man-in-the-Middle (MitM) scenario. In such an attack, the threat actor positions themselves between the ZTNA portal and the intended destination website, silently observing or altering the data exchange. Both the user and the backend application remain unaware, believing they are communicating over a trusted connection.

Fortinet has classified the resulting impact as information disclosure. A successful attack could expose sensitive data transmitted through the compromised channel, including session tokens or application content, without requiring any prior authentication credentials from the attacker. The unauthenticated nature of the attack vector significantly escalates the risk, particularly for organizations that expose their ZTNA portals to less secure network segments.

Affected Versions and Remediation

The vulnerability affects a specific range of product versions. For FortiOS, versions 7.6.1 through 7.6.6 are susceptible, while FortiOS 8.0, 7.4, and 7.2 branches are confirmed to be safe. Similarly, FortiProxy versions 7.6.2 through 7.6.6 are exposed, with FortiProxy 8.0, 7.4, and 7.2 remaining unaffected.

Fortinet’s recommended solution is straightforward: administrators currently operating the affected 7.6 branch of either product should promptly upgrade to version 7.6.7 or a later release. The vendor has also provided an official upgrade path tool to assist customers in planning a seamless migration without disrupting existing ZTNA policies.

As of the disclosure, there is no evidence to suggest that CVE-2026-84393 has been actively exploited in the wild, and Fortinet does not list it as a known exploited vulnerability.

What You Should Do

  • Prioritize Patching: Immediately upgrade FortiOS installations from versions 7.6.1 through 7.6.6 to version 7.6.7 or newer.
  • Upgrade FortiProxy: For FortiProxy deployments, upgrade versions 7.6.2 through 7.6.6 to version 7.6.7 or newer without delay.
  • Consult Fortinet Resources: Utilize Fortinet’s official upgrade path tool to ensure a smooth and disruption-free migration process.
  • Monitor ZTNA Portals: Given that ZTNA portals are often internet-facing, organizations should treat this update as critical due to the unauthenticated attack vector.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, including 2 zero-days

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Ivanti EPMM, Neurons, Sentry Flaws Allow RCE, Privilege Escalation
September 8, 2026
ChatGPT Sandbox Flaw Exposes Gmail Data to Account Takeover
September 8, 2026
Dell Secure Connect Gateway Critical Flaws Let Attackers Gain Unauthorized Access
September 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us