CVE-2026-84393
FortiOS and FortiProxy ZTNA portal improper certificate validation allows man-in-the-middle (CVE-2026-84393)
FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6 are affected by an improper certificate validation flaw in the Agentless ZTNA portal that may allow a remote unauthenticated attacker to perform a man-in-the-middle attack. No fixed release is listed yet.
What happened
Fortinet describes an improper certificate validation vulnerability in the Agentless ZTNA portal in FortiOS and FortiProxy. A remote unauthenticated attacker may be able to perform a man-in-the-middle attack on the communication channel between the ZTNA portal and the backend destination website.
The CVE description notes information disclosure; Fortinet's advisory focuses on the man-in-the-middle risk. The flaw is reachable over the network, requires no privileges and no user interaction, but has high attack complexity. It is rated high severity with a CVSS 3.1 score of 7.3.
Fortinet has not stated active exploitation, and the vulnerability is not listed in CISA KEV.
Who is affected
The affected products and versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6. The flaw is in the Agentless ZTNA portal. Organisations using these releases as ZTNA or secure access gateways should review their exposure.
What to do now
- Confirm whether you run FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6, especially where the Agentless ZTNA portal is enabled.
- No fixed versions are listed yet. Until Fortinet publishes a fix, restrict network reachability of the ZTNA portal to trusted networks where possible.
- Review the Fortinet PSIRT advisory FG-IR-26-174 for updated fixed versions or workarounds.
- If the portal cannot be restricted, review what backend destinations are reachable through it and apply additional controls until the issue is resolved.
Beyond the patch
Beyond the patch itself, this is an edge-device exposure issue: a network-reachable flaw without credentials is the kind of thing Virtual CISO Services (vCISO) can help you find and control before a fix exists. Because the risk sits in a vendor's software, Supply Chain Defense & Third-Party Risk supports keeping the Fortinet estate tracked and advisory responses accountable.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| FortiOS | 7.6.1 – ≤ 7.6.6 | No fixed version listed yet |
| FortiProxy | 7.6.2 – ≤ 7.6.6 | No fixed version listed yet |