Fortinet has disclosed a high-severity security vulnerability in the Agentless ZTNA portal of FortiOS and FortiProxy that could allow a remote attacker to intercept traffic between the ZTNA portal and a backend website.
The vulnerability, tracked as CVE-2026-84393, was disclosed on September 8, 2026, and has a CVSS score of 7.3.
Certificate Validation Weakness
The flaw is caused by improper certificate validation in the Agentless ZTNA portal. The issue is classified as CWE-295: Improper Certificate Validation.
ZTNA portals help users securely access internal applications without requiring a traditional VPN client. They rely on trusted connections between the portal and backend services.
However, because of this vulnerability, an attacker positioned on the network path could potentially use a forged or incorrect certificate to interfere with the connection.
Attackers Could Intercept Traffic
A successful attack could create a man-in-the-middle (MITM) situation.
An attacker could position themselves between the ZTNA portal and the backend website and potentially:
- Intercept sensitive traffic
- View application data or session information
- Manipulate communications between the two systems
The attack does not require authentication, making the issue more concerning for organizations with exposed ZTNA portals.
Fortinet has classified the potential impact as information disclosure.
Affected FortiOS and FortiProxy Versions
The vulnerability affects specific releases in the 7.6 branch.
FortiOS
- 7.6.1 through 7.6.6 — Affected
- 7.6.7 and later — Fixed
- 7.2, 7.4 and 8.0 — Not affected
FortiProxy
- 7.6.2 through 7.6.6 — Affected
- 7.6.7 and later — Fixed
- 7.2, 7.4 and 8.0 — Not affected
Fortinet Recommends Immediate Patching
Fortinet recommends that customers running affected versions upgrade to FortiOS or FortiProxy 7.6.7 or later.
Administrators should review their ZTNA deployments and plan the upgrade carefully to ensure existing access policies continue working as expected.
There is currently no evidence that CVE-2026-84393 has been exploited in the wild, and it is not currently listed as a known exploited vulnerability.
Why Organizations Should Pay Attention
ZTNA portals are often exposed to the internet or less-trusted network environments. A vulnerability that can be exploited without authentication therefore deserves prompt attention.
Organizations using Agentless ZTNA on affected FortiOS or FortiProxy versions should prioritize upgrading to 7.6.7 or later and continue monitoring their environments for unusual network activity.
Keeping security gateways and access platforms patched is critical because these systems sit directly between users and sensitive applications.