Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Fortinet patched 10 vulnerabilities across its product suite, including two critical flaws with CVSS scores of 9.6 and 9.1 CVE-2026-84390 (CVSS 9.6) allows unauthenticated attackers to bypass authentication via forged or reused JWTs in the FortiMonitorOnSight web portal CVE-2026-84388 (CVSS 9.1) enables proxying of user browser traffic through a compromised Chrome extension if the user visits a malicious site High-severity bugs in FortiSandbox and FortiOS/FortiProxy Agentless ZTNA portal allow i
Analysis
TL;DR
- Fortinet patched 10 vulnerabilities across its product suite, including two critical flaws with CVSS scores of 9.6 and 9.1
- CVE-2026-84390 (CVSS 9.6) allows unauthenticated attackers to bypass authentication via forged or reused JWTs in the FortiMonitorOnSight web portal
- CVE-2026-84388 (CVSS 9.1) enables proxying of user browser traffic through a compromised Chrome extension if the user visits a malicious site
- High-severity bugs in FortiSandbox and FortiOS/FortiProxy Agentless ZTNA portal allow information disclosure and man-in-the-middle attacks respectively
- No evidence of active exploitation in the wild; coordinated upgrades required for FortiPAM and the Chrome extension to fully remediate
Why It Matters
This release underscores the persistent risks of authentication bypass vulnerabilities in enterprise security products, particularly those involving JWT handling and browser extension trust boundaries. For AI practitioners and security professionals, it highlights the importance of supply chain and extension-based attack surfaces in zero-trust architectures.
Technical Details
- CVE-2026-84390 (CVSS 9.6): Sensitive information inclusion in source code within FortiMonitorOnSight; enables JWT forgery/reuse for unauthenticated access bypass
- CVE-2026-84388 (CVSS 9.1): Improper authentication in Fortinet Privileged Access Agent Chrome extension; allows browser traffic proxying via malicious website visit
- CVE-2026-26084 (High): FortiSandbox vulnerability enabling access to sensitive information
- CVE-2026-84393 (High): FortiOS and FortiProxy Agentless ZTNA portal flaw allowing man-in-the-middle attacks
- Remediation: FortiPAM must be upgraded to version 1.9.1 or 1.8.4, and the Chrome extension to 8.0.1.123 or above; medium/low-severity patches also address DoS, arbitrary code execution, process termination, and site redirection risks across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM, and other products
Industry Insight
- Organizations relying on Fortinet's zero-trust and privileged access management stack should prioritize the coordinated upgrade of both FortiPAM and the Chrome extension, as partial remediation leaves the attack chain intact
- The JWT-based authentication bypass reinforces the need for rigorous token validation and rotation policies across all web-facing security portals
- The breadth of vulnerabilities across Fortinet's product line suggests a systemic review of third-party component dependencies and extension trust models is warranted for enterprises in similar positions
Disclaimer: The above content is generated by AI and is for reference only.