Download Privacy Needle App

Type to search

Cybersecurity

Fortinet fixes critical authentication bypass and traffic proxying vulnerabilities

Share
Fortinet Firewall Hacked

Fortinet has released security patches to address several critical vulnerabilities affecting its product suite, including flaws that allow unauthenticated attackers to bypass authentication and intercept browser traffic.

The most severe defect, tracked as CVE-2026-84390, carries a CVSS score of 9.6. This vulnerability affects the FortiMonitorOnSight web portal and involves the inclusion of sensitive information within the source code. An unauthenticated remote attacker could exploit this flaw to bypass authentication mechanisms by using a forged or reused JSON Web Token (JWT).

A second critical vulnerability, CVE-2026-84388, holds a CVSS score of 9.1 and impacts the Fortinet Privileged Access Agent Chrome extension. If a user visits a malicious website, an unauthenticated attacker could exploit this improper authentication issue to proxy the user’s browser traffic.

Fixing the flaws in the Chrome extension requires coordinated updates across multiple components. Fortinet stated that customers must upgrade FortiPAM to version 1.9.1 or 1.8.4 to secure the environment. Additionally, the Fortinet Privileged Access Agent Chrome extension must be updated to version 8.0.1.123 or higher.

Beyond these critical issues, the company also addressed high-severity vulnerabilities in other core products. These include CVE-2026-26084 in FortiSandbox and CVE-2026-84393 in FortiOS and the FortiProxy Agentless ZTNA portal. The latter could facilitate man-in-the-middle (MitM) attacks, while both could allow unauthorised access to sensitive information.

The patch release also covers several medium- and low-severity issues across a wide range of Fortinet services, including FortiManager, FortiAnalyzer, FortiSOAR, FortiClient for Windows, FortiSIEM, and FortiProxy. Successful exploitation of these various flaws could result in several different security compromises, such as bypassing approval workflows, executing arbitrary code, or causing denial-of-service (DoS) conditions.

Other potential impacts from these additional flaws include the ability to inject broadcast messages, terminate processes, crash the httpsd daemon, or redirect users to arbitrary websites. While the severity of these vulnerabilities is significant, Fortinet has not reported any evidence that these flaws are currently being exploited in the wild.

Security administrators are encouraged to review the company’s PSIRT advisories and apply the necessary updates immediately to mitigate the risk of unauthorised access or traffic interception.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.