CyberSecurityNews

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack


Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website.

Tracked as CVE-2026-84393 and documented under advisory FG-IR-26-174, the issue was published on September 8, 2026, and carries a CVSSv3 score of 7.3.

The vulnerability stems from an improper certificate validation weakness, classified as CWE-295, within the Agentless ZTNA portal component. Zero Trust Network Access portals are designed to broker secure, identity-verified connections between end users and internal applications without requiring a full VPN client.

When certificate validation on the backend connection doesn’t properly enforce certificate validation, an attacker on the network path can present a forged or mismatched certificate and go undetected.

This opens the door to a classic man-in-the-middle scenario, where the attacker sits between the ZTNA portal and the destination website, silently observing or tampering with the session while both endpoints believe the connection is trusted.

Fortinet has classified the resulting impact as information disclosure, since a successful attacker could potentially view sensitive data traversing the compromised channel, including session details or application content, without needing any authentication credentials.

The attack vector is unauthenticated, meaning no prior access or valid login is required, which increases the practical risk for organizations that expose ZTNA portals to less trusted network segments.

The bug affects a fairly narrow band of releases. On the FortiOS side, versions 7.6.1 through 7.6.6 are vulnerable, while FortiOS 8.0, 7.4, and 7.2 branches are confirmed unaffected. FortiProxy carries a similar footprint, with versions 7.6.2 through 7.6.6 exposed, while FortiProxy 8.0, 7.4, and 7.2 remain unaffected.

Fortinet’s recommended remediation is straightforward: administrators running the affected 7.6 branch of either product should upgrade to version 7.6.7 or later. The vendor has also pointed customers toward its official upgrade path tool to help plan a smooth migration without disrupting existing ZTNA policies.

There is currently no evidence that CVE-2026-84393 has been exploited in the wild, and Fortinet’s tracking confirms it is not listed as a known exploited vulnerability at this time.

Because ZTNA portals are typically internet-facing or exposed to semi-trusted zones by design, organizations relying on Agentless ZTNA in FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 should prioritize patching to 7.6.7 promptly rather than treating this as a routine maintenance update, since the unauthenticated attack path meaningfully increases exposure until remediation is complete.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link