Special Bulletins
Critical Vulnerabilities in Fortinet's FortiMonitorOnSight and Privileged Access Agent Chrome Extension
H-ISAC Vulnerability Bulletins TLP WHITE: Critical Vulnerabilities in Fortinet's FortiMonitorOnSight and Privileged Access Agent Chrome Extension (CVE-2026-84390 & CVE-2026-84388)
Fortinet has issued security updates addressing 10 vulnerabilities across various products. Key flaws include an authentication bypass flaw in the FortiMonitorOnSight web portal that uses forged JSON Web Tokens (CVE-2026-84390) and a proxy flaw in the Fortinet Privileged Access Agent Chrome extension (CVE-2026-84388).
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: