CVE Tools
Back to feed
Patch released FortiMonitorOnSight auth-bypass Privileged Access Agent Chrome extension Fortinet web-app

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

SecurityWeek·By Ionut Arghire··1 min read
CVE Tools coverage

Fortinet has issued patches for ten security vulnerabilities across multiple products, addressing two critical defects requiring immediate attention. The most severe issue, CVE-2026-84390, allows unauthenticated attackers to bypass authentication on the FortiMonitorOnSight web portal by exploiting a forged JWT, while CVE-2026-84388 enables traffic proxying through the Privileged Access Agent Chrome extension.

To fully remediate these risks, administrators must upgrade FortiPAM to version 1.9.1 or 1.8.4 and ensure the associated Chrome extension is updated to version 8.0.1.123 or later. The update cycle also resolves high-severity bugs in FortiSandbox and FortiOS, along with several lower-severity issues affecting other components such as FortiManager and FortiClient.