CVE Tools

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

SecurityWeekBy Ionut Arghire

PatchFortiMonitorOnSightPrivileged Access Agent Chrome extension

Our summary

Fortinet has issued patches for ten security vulnerabilities across multiple products, addressing two critical defects requiring immediate attention. The most severe issue, CVE-2026-84390, allows unauthenticated attackers to bypass authentication on the FortiMonitorOnSight web portal by exploiting a forged JWT, while CVE-2026-84388 enables traffic proxying through the Privileged Access Agent Chrome extension.

To fully remediate these risks, administrators must upgrade FortiPAM to version 1.9.1 or 1.8.4 and ensure the associated Chrome extension is updated to version 8.0.1.123 or later. The update cycle also resolves high-severity bugs in FortiSandbox and FortiOS, along with several lower-severity issues affecting other components such as FortiManager and FortiClient.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store