CVE-2026-84393: High severity Fortinet FortiOS vulnerability
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
fortinet/fortiosto a version that resolves this vulnerability.Fixed in 7.6.7 - Upgrade
Upgrade
fortinet/fortiosto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
fortinet/fortiproxyto a version that resolves this vulnerability.Fixed in 7.6.7 - Upgrade
Upgrade
fortinet/fortiproxyto a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network-based exploitation with no privileges required and no user interaction, although attack complexity is rated high.
Which deployments are in scope for remediation?
FortiOS versions 7.6.1 through 7.6.6 and FortiProxy versions 7.6.2 through 7.6.6 are affected.
Is the specific exploitation path available in the advisory data?
No. The vulnerability description leaves the attack vector unspecified, so the provided data does not identify the affected feature, configuration, or network path.