Release roundup
Fortinet week 37 2026: critical FortiMonitorOnSight authentication bypass leads 10 CVEs
Fortinet's week 37 2026 release covers 10 CVEs: one critical, two high, five medium and two low. The standout is CVE-2026-84390, an unauthenticated authentication bypass in FortiMonitorOnSight. No CVEs are listed as exploited or in CISA KEV, and no fixed versions are listed.
The release at a glance
Fortinet published 10 CVEs in its week 37 2026 release, with a severity split of one critical, two high, five medium and two low. None is marked exploited and none appears in CISA's KEV catalogue. The more serious issues are concentrated in network-facing management and portal components, led by a critical authentication-bypass weakness in FortiMonitorOnSight and high-rated access-control and certificate-validation flaws in FortiSandbox and FortiOS/FortiProxy.
At the time of writing, the release data does not list fixed versions for any of the 10 CVEs. That makes exposure review and monitoring of Fortinet's advisories the immediate priority.
What matters most
FortiMonitorOnSight — CVE-2026-84390 is the priority. It is a critical source-code inclusion flaw (CVSS 9.6) that may allow a remote, unauthenticated attacker to bypass authentication by forging or reusing JWTs. The weakness requires no credentials and has total technical impact. Affected versions are 7.2.4 through 7.2.7 and 7.2.0 through 7.2.2. This CVE has its own advisory page on this site.
FortiSandbox family — CVE-2026-26084 is a high-severity improper access-control flaw (CVSS 8.9) allowing unauthenticated access to sensitive information via crafted HTTP requests. Affected products include FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8 and 4.2.1 through 4.2.8, plus FortiSandbox Cloud and FortiSandbox PaaS 5.0.4 through 5.0.5. CVE-2026-84387 is a medium command injection (CVSS 6.7) that a privileged attacker can use to execute unauthorized code or commands; affected versions include FortiSandbox 5.2.0, 5.0.0 through 5.0.6, 4.4.0 through 4.4.9 and 4.2.1 through 4.2.8.
FortiOS and FortiProxy — CVE-2026-84393 is a high-severity certificate-validation weakness (CVSS 7.3) that may allow a remote unauthenticated attacker to perform a man-in-the-middle attack between the Agentless ZTNA portal and the backend website. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6.
Other products that stand out:
- FortiAnalyzer CVE-2026-84391 (CVSS 5.9) — authenticated denial of service via SNMP GETBULK requests.
- FortiSOAR CVE-2026-84385 (CVSS 4.9) — an authenticated attacker with zero permissions can subscribe to websocket streams and inject broadcast messages.
- FortiManager CVE-2026-22575 (CVSS 4.7) — an administrator can bypass workflow approval.
- FortiClientWindows CVE-2026-84386 (CVSS 4.7) — a local unverified-ownership weakness allowing an authenticated attacker to terminate processes.
Patch in this order
No fixed versions are listed for this release, so the priorities below are an exposure-reduction and monitoring plan rather than a set of patch versions.
- FortiMonitorOnSight CVE-2026-84390 — critical, remotely reachable and unauthenticated. Confirm whether the web portal is exposed and restrict access until an update is available.
- FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS CVE-2026-26084 — high severity and unauthenticated. Review web UI exposure and tightly control network reachability.
- FortiOS and FortiProxy CVE-2026-84393 — high severity with remote unauthenticated man-in-the-middle risk to the Agentless ZTNA portal. Assess whether that portal needs to be internet-facing.
- FortiSandbox CVE-2026-84387 — medium severity but enables command execution for a privileged attacker; address after the unauthenticated network issues.
- FortiAnalyzer, FortiSOAR and FortiManager CVE-2026-84391, CVE-2026-84385 and CVE-2026-22575 — medium-severity authenticated issues. Prioritise according to product exposure and role separation.
- FortiClientWindows, FortiSIEM and FortiOS, FortiProxy and FortiPAM CVE-2026-84386, CVE-2026-84389 and CVE-2026-84392 — lower severity or local access; include in the routine update cycle and monitor for fixed versions.
Beyond the patch
Several of the more serious Fortinet issues this week are reachable without credentials on network-facing portals, which is precisely what an exposure review should catch. A Virtual CISO Services engagement can map which services are actually reachable and prioritise reduction measures; for the FortiSIEM open redirect, Digital Risk Protection can watch for phishing domains that try to weaponise it.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-84390 | FortiMonitorOnSight | Critical 9.6 | Advisory → |
| CVE-2026-26084 | FortiSandbox PaaS | High 8.9 | |
| CVE-2026-84393 | FortiOS | High 7.3 | Advisory → |
| CVE-2026-84387 | FortiSandbox | Medium 6.7 | |
| CVE-2026-84391 | FortiAnalyzer | Medium 5.9 | |
| CVE-2026-84385 | FortiSOAR on-premise | Medium 4.9 | |
| CVE-2026-22575 | FortiManager | Medium 4.7 | |
| CVE-2026-84386 | FortiClientWindows | Medium 4.7 | |
| CVE-2026-84389 | FortiSIEM | Low 2.8 | |
| CVE-2026-84392 | FortiOS | Low 2.5 |
References
Vendor advisory
- fortiguard.fortinet.com/psirt/FG-IR-26-170
- fortiguard.fortinet.com/psirt/FG-IR-26-166
- fortiguard.fortinet.com/psirt/FG-IR-26-174
- fortiguard.fortinet.com/psirt/FG-IR-26-167
- fortiguard.fortinet.com/psirt/FG-IR-26-172
- fortiguard.fortinet.com/psirt/FG-IR-26-164
- fortiguard.fortinet.com/psirt/FG-IR-26-171
- fortiguard.fortinet.com/psirt/FG-IR-26-165
CVE
- CVE-2026-84390 — cve.org
- CVE-2026-84390 — NVD
- CVE-2026-26084 — cve.org
- CVE-2026-26084 — NVD
- CVE-2026-84393 — cve.org
- CVE-2026-84393 — NVD
- CVE-2026-84387 — cve.org
- CVE-2026-84387 — NVD
- CVE-2026-84391 — cve.org
- CVE-2026-84391 — NVD
- CVE-2026-84385 — cve.org
- CVE-2026-84385 — NVD
- CVE-2026-22575 — cve.org
- CVE-2026-22575 — NVD
- CVE-2026-84386 — cve.org
- CVE-2026-84386 — NVD
- CVE-2026-84389 — cve.org
- CVE-2026-84389 — NVD
- CVE-2026-84392 — cve.org
- CVE-2026-84392 — NVD