Fortinet patches critical JWT bypass and Chrome proxy bug

Fortinet issued fixes for 10 vulnerabilities, including a FortiMonitorOnSight JWT authentication bypass (CVE-2026-84390) and a Privileged Access Agent Chrome extension proxy bug (CVE-2026-84388).

Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including two rated critical. The most severe, CVE-2026-84390 (CVSS 9.6), stems from sensitive information included in source code for the FortiMonitorOnSight web portal and can allow a remote, unauthenticated attacker to bypass authentication by presenting a forged or reused JSON Web Token. The second critical flaw, CVE-2026-84388 (CVSS 9.1), is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension that could let an attacker proxy a user’s browser traffic if the user visits a malicious site.

Fortinet advised: “Remediation for this issue required coordinated changes in two components: FortiPAM and the Fortinet Privileged Access Agent Chrome extension. To be fully secure, customers should upgrade FortiPAM to 1.9.1 or 1.8.4, and ensure the Chrome extension is at version 8.0.1.123 or above.”

The vendor also patched a high-severity information-disclosure bug in FortiSandbox (CVE-2026-26084) and a high-severity flaw in the FortiOS and FortiProxy Agentless ZTNA portal (CVE-2026-84393) that could enable man-in-the-middle attacks. Remaining fixes cover medium- and low-severity issues in FortiManager, FortiAnalyzer, FortiSandbox, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy and FortiPAM.

Fortinet’s advisory notes that successful exploitation of the patched vulnerabilities could allow attackers to bypass approval workflows, cause denial-of-service conditions, execute arbitrary code, inject broadcast messages, terminate processes, crash the httpsd daemon or redirect users to arbitrary sites. The company reported no confirmed exploitation of these flaws in the wild.

Fortinet’s Product Security Incident Response Team has published technical advisories with patch details and recommended updates. Administrators running affected products should apply the vendor updates and ensure the Privileged Access Agent Chrome extension is updated to the specified version to complete mitigation.

Articles by this author