Vulnerabilities & PatchesEmerging1 src
FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website.
Tracked as CVE-2026-84393 and documented under advisory FG-IR-26-174, the issue was published on September 8, 2026, and carries a CVSSv3 score of 7.3.
The vulnerability stems from an improper certificate validation weakness, classified as CWE-295, within the Agentless ZTNA portal component. Zero Trust Network Access portals are designed to broker secure, identity-verified connections between end users and internal applications without requiring a full VPN client.