Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

0
Critical
Vulnerability
Published: 09/09/2026 (09/09/2026, 14:33:52 UTC)
Source: SecurityWeek

Description

Fortinet released patches for multiple vulnerabilities including critical unauthenticated flaws in FortiMonitorOnSight and the Fortinet Privileged Access Agent Chrome extension. The critical issues allow attackers to bypass authentication using forged or reused JSON Web Tokens and proxy a user's browser traffic by exploiting improper authentication in the Chrome extension. Coordinated updates to FortiPAM and the Chrome extension are required for full remediation. Additional high-severity and medium/low-severity vulnerabilities affecting other Fortinet products were also patched. No exploitation in the wild has been reported.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 14:37:20 UTC

Technical Analysis

Fortinet patched 10 vulnerabilities across its product portfolio, including two critical unauthenticated bugs. CVE-2026-84390 affects the FortiMonitorOnSight web portal, allowing remote attackers to bypass authentication via forged or reused JSON Web Tokens. CVE-2026-84388 affects the Fortinet Privileged Access Agent Chrome extension, enabling remote attackers to proxy a user's browser traffic if the user visits a malicious website. Remediation requires upgrading FortiPAM to versions 1.9.1 or 1.8.4 and the Chrome extension to version 8.0.1.123 or later. Additional high-severity issues in FortiSandbox, FortiOS, and FortiProxy were also addressed, along with several medium- and low-severity flaws in other Fortinet products. No known exploitation in the wild has been reported by Fortinet.

Potential Impact

Successful exploitation of CVE-2026-84390 allows unauthenticated attackers to bypass authentication on the FortiMonitorOnSight portal, potentially gaining unauthorized access. CVE-2026-84388 enables attackers to proxy a user's browser traffic via the Fortinet Privileged Access Agent Chrome extension, which could lead to interception or manipulation of user traffic. Other patched vulnerabilities could allow sensitive information disclosure, man-in-the-middle attacks, denial-of-service, arbitrary code execution, and other impacts depending on the specific flaw. No active exploitation has been reported.

Mitigation Recommendations

Fortinet has released official patches addressing these vulnerabilities. To fully remediate the critical Chrome extension vulnerability, customers must upgrade FortiPAM to version 1.9.1 or 1.8.4 and update the Fortinet Privileged Access Agent Chrome extension to version 8.0.1.123 or later. Users should apply these updates promptly. Additional patches for other affected Fortinet products should also be applied as per vendor advisories. No further mitigation steps are indicated beyond applying these official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.93,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/","fetched":true,"fetchedAt":"2026-09-09T14:37:13.384Z","wordCount":960}

Threat ID: 6aa16f19acd9273b49740498

Added to database: 09/09/2026, 14:37:13 UTC

Last enriched: 09/09/2026, 14:37:20 UTC

Last updated: 09/09/2026, 23:51:21 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses