CVE-2026-84393

HIGH

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <inser...

Affects 0 products across 1 vendor.

CVSS 3.18.1
EPSS0.2%
Percentile15th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-297: CWE-297
◆ AI Analysis — automated analysis, not human-reviewed

A high severity vulnerability (CVE-2026-84393) affects the target system. A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-84393?
A high severity vulnerability (CVE-2026-84393) affects the target system. A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
What is the CVSS score for CVE-2026-84393?
CVE-2026-84393 has CVSS 8.1 (High). Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.2%.
Is CVE-2026-84393 actively exploited?
No confirmed active exploitation of CVE-2026-84393 as of 2026-10-06.
How do I remediate CVE-2026-84393?
Apply vendor patches for CVE-2026-84393. Monitor Fortinet advisories.
What systems are affected by CVE-2026-84393?
CVE-2026-84393 affects: Fortinet.
Vulnerability Details
CVE IDCVE-2026-84393
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-09-08
Last Modified2026-09-10
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Fortinet &mdash; —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 27 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2026-26084 9.9 A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 throug... CVE-2025-59718 9.8 A improper verification of cryptographic signature vulnerability in Fortinet ... CVE-2025-64446 9.8 A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.... CVE-2017-17539 9.8 The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier a...
View all Fortinet CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →