Fortinet has revealed a critical certificate-validation vulnerability in the Agentless Zero Trust Network Access (ZTNA) portal components of FortiOS and FortiProxy. The flaw, officially registered as CVE-2026-84393, allows unauthenticated remote attackers to intercept traffic between the ZTNA portal and backend destination sites—potentially enabling man-in-the-middle (MITM) attacks. This weakness was publicized on September 8, 2026, in security advisory FG-IR-26-174, with a CVSS v3 score of 7.3.
How the Vulnerability Works
The issue arises because the Agentless ZTNA portal does not properly validate certificates when connecting back to the backend destination website. Under CWE-295 (Improper Certificate Validation), an attacker controlling the network path can present a forged or mismatched certificate without being detected. The affected component is designed to mediate secure, identity-verified access to internal applications without needing a full VPN client, but this vulnerability undermines the trust model.
When exploited, this vulnerability can allow an attacker to eavesdrop on or alter data as it moves between the ZTNA portal and web servers, all while both ends believe they are communicating securely. Because the flaw is exploitable without credentials or prior access—it’s an unauthenticated vector—its potential for harm increases significantly.
Affected Versions & Remediation
The vulnerability impacts specific releases of both FortiOS and FortiProxy. FortiOS versions 7.6.1 through 7.6.6 are vulnerable, whereas the 7.4, 7.2, and 8.0 branches are not affected. FortiProxy mirrors this pattern: versions 7.6.2 through 7.6.6 are exposed to the risk, while 7.4, 7.2, and 8.0 are safe.
To fix the issue, Fortinet advises users running any of the vulnerable 7.6.x versions to upgrade to version 7.6.7 or newer. The vendor has also published an upgrade-path tool to help organizations migrate without breaking existing ZTNA policies.
So far, there is no evidence that CVE-2026-84393 has been exploited in real attacks, and it is not listed among known exploited vulnerabilities by Fortinet or related security bodies. Despite this, the exposure is significant: ZTNA portals are often internet-facing or in semi-trusted zones, which amplifies risk until the patch is applied.
Organizations running FortiOS or FortiProxy Agentless ZTNA on the vulnerable 7.6 branches should consider this a high priority security update rather than routine maintenance. The unauthenticated attack path means that even just exposure to lower-trust networks could allow a breach.
What this means: The discovery underscores a lingering challenge in network security: ensuring backend certificate verification in systems meant to streamline secure access without full VPN burdens. As ZTNA adoption accelerates across enterprises looking to support remote work, cloud services, and hybrid environments, flaws like these risk undermining trust models foundational to secure access solutions.