CVE-2026-84393
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert a
Description
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
Weakness: CWE-297
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiProxy | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiOS
- Fortinet · FortiProxy
Credit
Internally discovered and reported by John Headley of the Fortinet System Engineering team.
Vendor remediation
Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.7 or above Upgrade to upcoming FortiProxy version 8.0.0 or above Upgrade to upcoming FortiProxy version 7.6.7 or above Fortinet remediated this issue in FortiSASE version 26.2.2 (not released) and hence customers do not need to perform any action.