FORTINET has released patches for ten vulnerabilities across its product line, including two critical flaws. The most severe is CVE-2026-84390, a source-code information exposure affecting the FortiMonitorOnSight web portal. Fortinet says a remote, unauthenticated attacker could bypass authentication by forging or reusing a JSON Web Token (JWT).
Another critical issue is CVE-2026-84388, an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension. A remote, unauthenticated attacker could proxy a user’s browser traffic if the user visits a malicious site. Remedy requires coordinated changes in FortiPAM and the Fortinet Privileged Access Agent Chrome extension; customers should upgrade FortiPAM to version 1.9.1 or 1.8.4 and ensure the Chrome extension is at 8.0.1[.]123 or newer.
In addition, Fortinet patched high-severity bugs including CVE-2026-26084 in FortiSandbox and CVE-2026-84393 affecting the FortiOS FortiProxy Agentless ZTNA portal, which could enable information disclosure and man-in-the-middle (MitM) attacks, respectively. The remaining fixes are medium- to low-severity issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy and FortiPAM.
Exploitation of these flaws could allow bypassing approval workflows, DoS, arbitrary code execution, broadcast message injection, process termination, httpsd crashes and arbitrary site redirections. Fortinet states that none of the vulnerabilities are known to be exploited in the wild, with advisories linked on its PSIRT page.