Skip to content
Auto-CTI
Back to today
NEW CRITICAL C3

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

C SecurityWeek ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The critical vulnerabilities allow unauthenticated attackers to bypass authentication using forged JWTs and proxy user browser traffic if users visit malicious websites,a direct risk to privileged access management.

Description

Fortinet has patched ten vulnerabilities across its products, including two critical defects. CVE-2026-84390 (CVSS 9.6) is an information disclosure vulnerability in the FortiMonitorOnSight web portal that allows unauthenticated attackers to gain access via forged or reused JSON Web Tokens (JWT). CVE-2026-84388 (CVSS 9.1) is an authentication vulnerability in the Fortinet Privileged Access Agent Chrome extension that allows attackers to proxy a user's browser traffic if the user visits a malicious website. Additional high-severity vulnerabilities were found in FortiSandbox and the FortiOS/FortiProxy Agentless ZTNA portal. According to Fortinet, there are currently no reports of active exploitation in the wild.

Risk score

70
cvss base
45.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
60.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC