{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-84393", "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8", "state": "PUBLISHED", "assignerShortName": "fortinet", "dateReserved": "2026-09-01T16:36:14.802Z", "datePublished": "2026-09-08T16:41:49.203Z", "dateUpdated": "2026-09-10T03:56:52.472Z" }, "containers": { "cna": { "affected": [ { "vendor": "Fortinet", "product": "FortiOS", "cpes": [ "cpe:2.3:o:fortinet:fortios:7.6.6:*:*:*:*:*:*:*", "cpe:2.3:o:fortinet:fortios:7.6.5:*:*:*:*:*:*:*", "cpe:2.3:o:fortinet:fortios:7.6.4:*:*:*:*:*:*:*", "cpe:2.3:o:fortinet:fortios:7.6.3:*:*:*:*:*:*:*", "cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:*", "cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "versions": [ { "versionType": "semver", "version": "7.6.1", "lessThanOrEqual": "7.6.6", "status": "affected" } ] }, { "vendor": "Fortinet", "product": "FortiProxy", "cpes": [ "cpe:2.3:a:fortinet:fortiproxy:7.6.6:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiproxy:7.6.5:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiproxy:7.6.4:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiproxy:7.6.3:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiproxy:7.6.2:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "versions": [ { "versionType": "semver", "version": "7.6.2", "lessThanOrEqual": "7.6.6", "status": "affected" } ] } ], "descriptions": [ { "lang": "en", "value": "A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via " } ], "providerMetadata": { "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8", "shortName": "fortinet", "dateUpdated": "2026-09-08T16:41:49.203Z" }, "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-297", "description": "Information disclosure", "type": "CWE" } ] } ], "metrics": [ { "format": "CVSS", "cvssV3_1": { "version": "3.1", "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.3, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C" } } ], "solutions": [ { "lang": "en", "value": "Upgrade to FortiOS version 8.0.0 or above\nUpgrade to FortiOS version 7.6.7 or above\nUpgrade to upcoming FortiProxy version 8.0.0 or above\nUpgrade to upcoming FortiProxy version 7.6.7 or above\nFortinet remediated this issue in FortiSASE version 26.2.2 (not released) and hence customers do not need to perform any action." } ], "references": [ { "name": "https://fortiguard.fortinet.com/psirt/FG-IR-26-174", "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-174" } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-09T00:00:00+00:00", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3", "id": "CVE-2026-84393" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-10T03:56:52.472Z" } } ] } }