Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.7 or above Upgrade to upcoming FortiProxy version 8.0.0 or above Upgrade to upcoming FortiProxy version 7.6.7 or above Fortinet remediated this issue in FortiSASE version 26.2.2 (not released) and hence customers do not need to perform any action.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-174 |
|
Tue, 08 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Certificate Host Validation Allows Information Disclosure |
Tue, 08 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here> | |
| First Time appeared |
Fortinet
Fortinet fortios Fortinet fortiproxy |
|
| Weaknesses | CWE-297 | |
| CPEs | cpe:2.3:a:fortinet:fortiproxy:7.6.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.6:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.3:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.4:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.5:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortios Fortinet fortiproxy |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-09-08T17:30:49.140Z
Reserved: 2026-09-01T16:36:14.802Z
Link: CVE-2026-84393
No data.
Status : Awaiting Analysis
Published: 2026-09-08T17:18:37.883
Modified: 2026-09-08T18:35:10.323
Link: CVE-2026-84393
No data.
OpenCVE Enrichment
Updated: 2026-09-08T18:00:11Z