Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.7 or above Upgrade to upcoming FortiProxy version 8.0.0 or above Upgrade to upcoming FortiProxy version 7.6.7 or above Fortinet remediated this issue in FortiSASE version 26.2.2 (not released) and hence customers do not need to perform any action.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-174 |
|
Tue, 08 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Certificate Host Validation Allows Information Disclosure |
Tue, 08 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here> | |
| First Time appeared |
Fortinet
Fortinet fortios Fortinet fortiproxy |
|
| Weaknesses | CWE-297 | |
| CPEs | cpe:2.3:a:fortinet:fortiproxy:7.6.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.6:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.3:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.4:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.5:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortios Fortinet fortiproxy |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-09-08T17:30:49.140Z
Reserved: 2026-09-01T16:36:14.802Z
Link: CVE-2026-84393
No data.
Status : Awaiting Analysis
Published: 2026-09-08T17:18:37.883
Modified: 2026-09-08T18:35:10.323
Link: CVE-2026-84393
No data.
OpenCVE Enrichment
Updated: 2026-09-08T18:00:11Z