Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    September 10, 2026

    APOD: 2026 September 10 – LDN 1295: The Giraffe Nebula

    September 10, 2026

    Jackery Explorer 2000 v2 portable power station review

    September 10, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
    Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
    Cybersecurity

    Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

    The Tech GuyBy The Tech GuySeptember 9, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects.

    Advertisement

    The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is described as an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal.

    A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT).

    The second critical vulnerability is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension, tracked as CVE-2026-84388 (CVSS score of 9.1).

    A remote, unauthenticated attacker may exploit the security defect to proxy a user’s browser traffic if the user visits a malicious website, Fortinet explains.

    “Remediation for this issue required coordinated changes in two components: FortiPAM and the Fortinet Privileged Access Agent Chrome extension. To be fully secure, customers should upgrade FortiPAM to 1.9.1 or 1.8.4, and ensure the Chrome extension is at version 8.0.1.123 or above,” the company notes.

    Advertisement. Scroll to continue reading.

    Fortinet also patched high-severity bugs in FortiSandbox (CVE-2026-26084) and FortiOS and FortiProxy Agentless ZTNA portal (CVE-2026-84393) that could allow attackers to access sensitive information and perform man-in-the-middle (MitM) attacks, respectively.

    The remaining vulnerabilities resolved on Tuesday are medium- and low-severity issues in FortiManager, FortiAnalyzer, FortiSandbox, FortiSOAR, FortiClient for Windows, FortiSIEM, FortiOS, FortiProxy, and FortiPAM.

    Successful exploitation of these flaws could allow attackers to bypass approval workflows, cause a denial-of-service (DoS) condition, execute arbitrary code, inject broadcast messages, terminate processes, crash the httpsd daemon, and cause redirections to arbitrary sites.

    Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page.

    Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

    Related: Ivanti Patches Critical Flaws Across Enterprise Security Products

    Related: Chrome 153 Patches Seventh Zero-Day of 2026

    Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    September 10, 2026

    AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

    September 10, 2026

    HelmGuard Raises $7.3 Million for Agentic GRC and Security

    September 9, 2026

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    September 9, 2026

    Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    September 8, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    September 10, 2026

    APOD: 2026 September 10 – LDN 1295: The Giraffe Nebula

    September 10, 2026

    Jackery Explorer 2000 v2 portable power station review

    September 10, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.