[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fX6OGCTKyKK6c1qPk6xBw1zdKUlUFzD9Z-L32HnmfJaA":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"246d10ab-ddd1-4447-a5f2-6112deb0b0f9","Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension","fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extensio-656eca","The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.","Fortinet has issued patches for 10 vulnerabilities across its product line, with two critical flaws being the most significant. CVE-2026-84390, a critical vulnerability in the FortiMonitorOnSight web portal, allows unauthenticated attackers to bypass authentication. Another critical flaw, CVE-2026-84388, in the Fortinet Privileged Access Agent Chrome extension, enables attackers to proxy user browser traffic. Fortinet also addressed high-severity bugs in FortiSandbox and FortiOS\u002FFortiProxy, alongside medium and low-severity issues in various other products.","Fortinet releases patches for 10 vulnerabilities, including two critical flaws in FortiMonitorOnSight and a Chrome","Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects. The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is described as an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal. A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT). The second critical vulnerability is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension, tracked as CVE-2026-84388 (CVSS score of 9.1). A remote, unauthenticated attacker may exploit the security defect to proxy a user’s browser traffic if the user visits a malicious website, Fortinet explains. “Remediation for this issue required coordinated changes in two components: FortiPAM and the Fortinet Privileged Access Agent Chrome extension. To be fully secure, customers should upgrade FortiPAM to 1.9.1 or 1.8.4, and ensure the Chrome extension is at version 8.0.1.123 or above,” the company notes.Advertisement. Scroll to continue reading. Fortinet also patched high-severity bugs in FortiSandbox (CVE-2026-26084) and FortiOS and FortiProxy Agentless ZTNA portal (CVE-2026-84393) that could allow attackers to access sensitive information and perform man-in-the-middle (MitM) attacks, respectively. The remaining vulnerabilities resolved on Tuesday are medium- and low-severity issues in FortiManager, FortiAnalyzer, FortiSandbox, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy, and FortiPAM. Successful exploitation of these flaws could allow attackers to bypass approval workflows, cause a denial-of-service (DoS) condition, execute arbitrary code, inject broadcast messages, terminate processes, crash the httpsd daemon, and cause redirections to arbitrary sites. Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page. Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws Related: Ivanti Patches Critical Flaws Across Enterprise Security Products Related: Chrome 153 Patches Seventh Zero-Day of 2026 Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayHackers Return $263 Million Stolen From Liquid NetworkSAP Patches Critical Extended Passport Processing VulnerabilityMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage Toolkit Latest News US Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesMeta Launches Personal AI Agent, Muse, Emphasizes Safety and PrivacyICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsIvanti Patches Critical Flaws Across Enterprise Security ProductsNew Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserThis Key Will Self-Destruct: An Open Standard for Revocable API KeysChrome 153 Patches Seventh Zero-Day of 2026Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Ffortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F06\u002Ffortinet.jpg","2026-09-09T14:33:52+00:00","2026-09-09T16:00:06.213252+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"Fortinet","vendor",{"name":22,"type":23},"FortiMonitorOnSight","product",{"name":25,"type":23},"Fortinet Privileged Access Agent Chrome extension",{"name":27,"type":23},"FortiPAM",{"name":29,"type":23},"FortiSandbox",{"name":31,"type":23},"FortiOS","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,40],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46,50,53,56],{"type":47,"value":48,"context":49},"cve","CVE-2026-84390","Critical vulnerability in FortiMonitorOnSight web portal",{"type":47,"value":51,"context":52},"CVE-2026-84388","Critical vulnerability in Fortinet Privileged Access Agent Chrome extension",{"type":47,"value":54,"context":55},"CVE-2026-26084","High-severity vulnerability in FortiSandbox",{"type":47,"value":57,"context":58},"CVE-2026-84393","High-severity vulnerability in FortiOS and FortiProxy Agentless ZTNA portal"]