Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
PatchFortiMonitorOnSightPrivileged Access Agent Chrome extensionOur summary
Fortinet has issued patches for ten security vulnerabilities across multiple products, addressing two critical defects requiring immediate attention. The most severe issue, CVE-2026-84390, allows unauthenticated attackers to bypass authentication on the FortiMonitorOnSight web portal by exploiting a forged JWT, while CVE-2026-84388 enables traffic proxying through the Privileged Access Agent Chrome extension.
To fully remediate these risks, administrators must upgrade FortiPAM to version 1.9.1 or 1.8.4 and ensure the associated Chrome extension is updated to version 8.0.1.123 or later. The update cycle also resolves high-severity bugs in FortiSandbox and FortiOS, along with several lower-severity issues affecting other components such as FortiManager and FortiClient.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.