Fortinet Releases Patches for Critical FortiMonitorOnSight and Chrome Extension Flaws
Fortinet released patches for 10 vulnerabilities across its products, including multiple critical security flaws. CVE-2026-84390 (FortiMonitorOnSight) could let remote, unauthenticated attackers bypass authentication via forged or reused JWTs. CVE-2026-84388 (Privileged Access Agent Chrome extension) could allow unauthenticated interception of browser traffic. Updates also address high-severity issues enabling sensitive data access and MitM attacks, plus several medium- and low-severity fixes.