Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Fortinet released patches for multiple vulnerabilities including critical unauthenticated flaws in FortiMonitorOnSight and the Fortinet Privileged Access Agent Chrome extension. The critical issues allow attackers to bypass authentication using forged or reused JSON Web Tokens and proxy a user's browser traffic by exploiting improper authentication in the Chrome extension. Coordinated updates to FortiPAM and the Chrome extension are required for full remediation. Additional high-severity and medium/low-severity vulnerabilities affecting other Fortinet products were also patched. No exploitation in the wild has been reported.
AI Analysis
Technical Summary
Fortinet patched 10 vulnerabilities across its product portfolio, including two critical unauthenticated bugs. CVE-2026-84390 affects the FortiMonitorOnSight web portal, allowing remote attackers to bypass authentication via forged or reused JSON Web Tokens. CVE-2026-84388 affects the Fortinet Privileged Access Agent Chrome extension, enabling remote attackers to proxy a user's browser traffic if the user visits a malicious website. Remediation requires upgrading FortiPAM to versions 1.9.1 or 1.8.4 and the Chrome extension to version 8.0.1.123 or later. Additional high-severity issues in FortiSandbox, FortiOS, and FortiProxy were also addressed, along with several medium- and low-severity flaws in other Fortinet products. No known exploitation in the wild has been reported by Fortinet.
Potential Impact
Successful exploitation of CVE-2026-84390 allows unauthenticated attackers to bypass authentication on the FortiMonitorOnSight portal, potentially gaining unauthorized access. CVE-2026-84388 enables attackers to proxy a user's browser traffic via the Fortinet Privileged Access Agent Chrome extension, which could lead to interception or manipulation of user traffic. Other patched vulnerabilities could allow sensitive information disclosure, man-in-the-middle attacks, denial-of-service, arbitrary code execution, and other impacts depending on the specific flaw. No active exploitation has been reported.
Mitigation Recommendations
Fortinet has released official patches addressing these vulnerabilities. To fully remediate the critical Chrome extension vulnerability, customers must upgrade FortiPAM to version 1.9.1 or 1.8.4 and update the Fortinet Privileged Access Agent Chrome extension to version 8.0.1.123 or later. Users should apply these updates promptly. Additional patches for other affected Fortinet products should also be applied as per vendor advisories. No further mitigation steps are indicated beyond applying these official fixes.
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Description
Fortinet released patches for multiple vulnerabilities including critical unauthenticated flaws in FortiMonitorOnSight and the Fortinet Privileged Access Agent Chrome extension. The critical issues allow attackers to bypass authentication using forged or reused JSON Web Tokens and proxy a user's browser traffic by exploiting improper authentication in the Chrome extension. Coordinated updates to FortiPAM and the Chrome extension are required for full remediation. Additional high-severity and medium/low-severity vulnerabilities affecting other Fortinet products were also patched. No exploitation in the wild has been reported.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Fortinet patched 10 vulnerabilities across its product portfolio, including two critical unauthenticated bugs. CVE-2026-84390 affects the FortiMonitorOnSight web portal, allowing remote attackers to bypass authentication via forged or reused JSON Web Tokens. CVE-2026-84388 affects the Fortinet Privileged Access Agent Chrome extension, enabling remote attackers to proxy a user's browser traffic if the user visits a malicious website. Remediation requires upgrading FortiPAM to versions 1.9.1 or 1.8.4 and the Chrome extension to version 8.0.1.123 or later. Additional high-severity issues in FortiSandbox, FortiOS, and FortiProxy were also addressed, along with several medium- and low-severity flaws in other Fortinet products. No known exploitation in the wild has been reported by Fortinet.
Potential Impact
Successful exploitation of CVE-2026-84390 allows unauthenticated attackers to bypass authentication on the FortiMonitorOnSight portal, potentially gaining unauthorized access. CVE-2026-84388 enables attackers to proxy a user's browser traffic via the Fortinet Privileged Access Agent Chrome extension, which could lead to interception or manipulation of user traffic. Other patched vulnerabilities could allow sensitive information disclosure, man-in-the-middle attacks, denial-of-service, arbitrary code execution, and other impacts depending on the specific flaw. No active exploitation has been reported.
Mitigation Recommendations
Fortinet has released official patches addressing these vulnerabilities. To fully remediate the critical Chrome extension vulnerability, customers must upgrade FortiPAM to version 1.9.1 or 1.8.4 and update the Fortinet Privileged Access Agent Chrome extension to version 8.0.1.123 or later. Users should apply these updates promptly. Additional patches for other affected Fortinet products should also be applied as per vendor advisories. No further mitigation steps are indicated beyond applying these official fixes.
Technical Details
- Classification
- {"confidence":0.93,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/","fetched":true,"fetchedAt":"2026-09-09T14:37:13.384Z","wordCount":960}
Threat ID: 6aa16f19acd9273b49740498
Added to database: 09/09/2026, 14:37:13 UTC
Last enriched: 09/09/2026, 14:37:20 UTC
Last updated: 09/09/2026, 23:51:21 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.