Description
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
Published: 2026-09-08
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an improper validation of certificates that allows a host mismatch to be accepted, which can enable attackers to obtain sensitive information from the device. The weakness is identified as CWE‑297, related to improper certificate validation.

Affected Systems

Affected products are FortiOS versions 7.6.1 through 7.6.6 and FortiProxy versions 7.6.2 through 7.6.6. Fortinet recommends upgrading to FortiOS 8.0.0 or 7.6.7 and FortiProxy 8.0.0 or 7.6.7. FortiSASE version 26.2.2 has already been remediated and requires no action.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, but the EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack vector is not explicitly documented; the description implies that an attacker could trigger the flaw via remote interaction involving certificate handling, potentially over the network. Consequently, the risk remains significant if the affected firmware or appliance remains unpatched.

Generated by OpenCVE AI on September 8, 2026 at 17:58 UTC.

Remediation

Vendor Solution

Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.7 or above Upgrade to upcoming FortiProxy version 8.0.0 or above Upgrade to upcoming FortiProxy version 7.6.7 or above Fortinet remediated this issue in FortiSASE version 26.2.2 (not released) and hence customers do not need to perform any action.


OpenCVE Recommended Actions

  • Upgrade FortiOS to version 8.0.0 or 7.6.7.
  • Upgrade FortiProxy to version 8.0.0 or 7.6.7.
  • If using FortiSASE, confirm the device is on version 26.2.2, which already includes the fix and no further action is required.

Generated by OpenCVE AI on September 8, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Improper Certificate Host Validation Allows Information Disclosure

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortios
Fortinet fortiproxy
Weaknesses CWE-297
CPEs cpe:2.3:a:fortinet:fortiproxy:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:7.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:7.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:7.6.6:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.3:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.4:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.5:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.6:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortios
Fortinet fortiproxy
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortios Fortiproxy
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-09-10T03:56:52.472Z

Reserved: 2026-09-01T16:36:14.802Z

Link: CVE-2026-84393

cve-icon Vulnrichment

Updated: 2026-09-08T17:30:39.071Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T17:18:37.883

Modified: 2026-09-10T04:18:18.120

Link: CVE-2026-84393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:00:11Z

Weaknesses
  • CWE-297

    Improper Validation of Certificate with Host Mismatch