Back to feed

Fortinet patches critical flaws in FortiMonitorOnSight and Chrome extension

2 min
Fortinet patches critical flaws in FortiMonitorOnSight and Chrome extension

This digest was compiled by AI from multiple sources — links to the originals are below.

Fortinet released patches for 10 vulnerabilities, including two critical flaws with CVSS scores of 9.6 and 9.1. The most severe affects the FortiMonitorOnSight web portal and could allow authentication bypass via a forged JWT. The other critical issue in the Fortinet Privileged Access Agent Chrome extension could let attackers proxy browser traffic.

Key Facts

  • CVE-2026-84390, with a CVSS score of 9.6, allows remote unauthenticated attackers to bypass authentication on the FortiMonitorOnSight web portal via a forged or reused JWT.
  • CVE-2026-84388, with a CVSS score of 9.1, is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can proxy a user's browser traffic when visiting a malicious website.
  • Fortinet advises customers to upgrade FortiPAM to 1.9.1 or 1.8.4 and the Chrome extension to version 8.0.1.123 or above for full remediation.
  • High-severity vulnerabilities were also patched in FortiSandbox (CVE-2026-26084) and the FortiOS and FortiProxy Agentless ZTNA portal (CVE-2026-84393).
  • Fortinet made no mention of any of the 10 vulnerabilities being exploited in the wild.

Critical Vulnerabilities

The first critical flaw, CVE-2026-84390, is an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal. A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT). The second critical vulnerability, CVE-2026-84388, is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension. A remote, unauthenticated attacker may exploit the security defect to proxy a user's browser traffic if the user visits a malicious website.

Remediation Guidance

Fortinet stated that remediation for CVE-2026-84388 required coordinated changes in FortiPAM and the Fortinet Privileged Access Agent Chrome extension. Customers should upgrade FortiPAM to 1.9.1 or 1.8.4 and ensure the Chrome extension is at version 8.0.1.123 or above. The company also patched high-severity bugs in FortiSandbox (CVE-2026-26084) and the FortiOS and FortiProxy Agentless ZTNA portal (CVE-2026-84393). These high-severity flaws could allow attackers to access sensitive information and perform man-in-the-middle attacks, respectively.

Additional Patches

The remaining vulnerabilities resolved on Tuesday are medium- and low-severity issues in FortiManager, FortiAnalyzer, FortiSandbox, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy, and FortiPAM. Successful exploitation of these flaws could allow attackers to bypass approval workflows, cause a denial-of-service condition, execute arbitrary code, inject broadcast messages, terminate processes, crash the httpsd daemon, and cause redirections to arbitrary sites. Fortinet makes no mention of any of these vulnerabilities being exploited in the wild.

1 source

Time · lag behind first