FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
Key Takeaways A high-severity vulnerability (CVE-2026-84393) has been discovered in FortiOS and FortiProxy Agentless ZTNA portals. The flaw allows an unauthenticated remote attacker to conduct a...
Key Takeaways
- A high-severity vulnerability (CVE-2026-84393) has been discovered in FortiOS and FortiProxy Agentless ZTNA portals.
- The flaw allows an unauthenticated remote attacker to conduct a Man-in-the-Middle (MitM) attack by exploiting improper certificate validation.
- Affected versions include FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6.
- A fix is available; administrators should upgrade to version 7.6.7 or later for both products.
Fortinet Discloses High-Severity ZTNA Vulnerability Enabling Man-in-the-Middle Attacks
Fortinet has issued a critical warning regarding a high-severity flaw impacting the Agentless Zero Trust Network Access (ZTNA) portal within its FortiOS and FortiProxy products. This vulnerability, if exploited, could allow an unauthenticated remote attacker to intercept and potentially manipulate traffic flowing between the ZTNA portal and backend destination websites.
Table Of Content
Technical Details of the Vulnerability
Designated CVE-2026-84393 and outlined in advisory FG-IR-26-174, the issue was publicly disclosed on September 8, 2026. It carries a CVSSv3 score of 7.3, reflecting its significant potential impact.
The core of the problem lies in an improper certificate validation mechanism, categorized under CWE-295, within the Agentless ZTNA portal. ZTNA portals are engineered to establish secure, verified connections between end-users and internal applications, circumventing the need for a full Virtual Private Network (VPN) client. However, when the backend connection fails to rigorously enforce certificate validation, an attacker positioned on the network path can introduce a forged or mismatched certificate, going undetected by the system.
This oversight creates a classic Man-in-the-Middle (MitM) scenario. In such an attack, the threat actor positions themselves between the ZTNA portal and the intended destination website, silently observing or altering the data exchange. Both the user and the backend application remain unaware, believing they are communicating over a trusted connection.
Fortinet has classified the resulting impact as information disclosure. A successful attack could expose sensitive data transmitted through the compromised channel, including session tokens or application content, without requiring any prior authentication credentials from the attacker. The unauthenticated nature of the attack vector significantly escalates the risk, particularly for organizations that expose their ZTNA portals to less secure network segments.
Affected Versions and Remediation
The vulnerability affects a specific range of product versions. For FortiOS, versions 7.6.1 through 7.6.6 are susceptible, while FortiOS 8.0, 7.4, and 7.2 branches are confirmed to be safe. Similarly, FortiProxy versions 7.6.2 through 7.6.6 are exposed, with FortiProxy 8.0, 7.4, and 7.2 remaining unaffected.
Fortinet’s recommended solution is straightforward: administrators currently operating the affected 7.6 branch of either product should promptly upgrade to version 7.6.7 or a later release. The vendor has also provided an official upgrade path tool to assist customers in planning a seamless migration without disrupting existing ZTNA policies.
As of the disclosure, there is no evidence to suggest that CVE-2026-84393 has been actively exploited in the wild, and Fortinet does not list it as a known exploited vulnerability.
What You Should Do
- Prioritize Patching: Immediately upgrade FortiOS installations from versions 7.6.1 through 7.6.6 to version 7.6.7 or newer.
- Upgrade FortiProxy: For FortiProxy deployments, upgrade versions 7.6.2 through 7.6.6 to version 7.6.7 or newer without delay.
- Consult Fortinet Resources: Utilize Fortinet’s official upgrade path tool to ensure a smooth and disruption-free migration process.
- Monitor ZTNA Portals: Given that ZTNA portals are often internet-facing, organizations should treat this update as critical due to the unauthenticated attack vector.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.