{"api_version":"1","generated_at":"2026-09-11T09:57:20+00:00","cve":"CVE-2026-84393","urls":{"html":"https://cve.report/CVE-2026-84393","api":"https://cve.report/api/cve/CVE-2026-84393.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-84393","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-84393"},"summary":{"title":"CVE-2026-84393","description":"A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>","state":"PUBLISHED","assigner":"fortinet","published_at":"2026-09-08 17:18:37","updated_at":"2026-09-10 04:18:18"},"problem_types":["CWE-297","CWE-297 Information disclosure"],"metrics":[{"version":"3.1","source":"psirt@fortinet.com","type":"Secondary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C","version":"3.1"}}],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-174","name":"https://fortiguard.fortinet.com/psirt/FG-IR-26-174","refsource":"psirt@fortinet.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-84393","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84393","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Fortinet","product":"FortiOS","version":"affected 7.6.1 7.6.6 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiProxy","version":"affected 7.6.2 7.6.6 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to FortiOS version 8.0.0 or above\nUpgrade to FortiOS version 7.6.7 or above\nUpgrade to upcoming  FortiProxy version 8.0.0 or above\nUpgrade to upcoming  FortiProxy version 7.6.7 or above\nFortinet remediated this issue in FortiSASE version 26.2.2 (not released) and hence customers do not need to perform any action.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"84393","cve":"CVE-2026-84393","epss":"0.001550000","percentile":"0.049510000","score_date":"2026-09-10","updated_at":"2026-09-11 00:05:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-84393","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-09T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T03:56:52.472Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:o:fortinet:fortios:7.6.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.6.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.6.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.6.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"FortiOS","vendor":"Fortinet","versions":[{"lessThanOrEqual":"7.6.6","status":"affected","version":"7.6.1","versionType":"semver"}]},{"cpes":["cpe:2.3:a:fortinet:fortiproxy:7.6.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.6.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.6.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.6.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.6.2:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"FortiProxy","vendor":"Fortinet","versions":[{"lessThanOrEqual":"7.6.6","status":"affected","version":"7.6.2","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>"}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-297","description":"Information disclosure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T16:41:49.203Z","orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet"},"references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-26-174","url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-174"}],"solutions":[{"lang":"en","value":"Upgrade to FortiOS version 8.0.0 or above\nUpgrade to FortiOS version 7.6.7 or above\nUpgrade to upcoming  FortiProxy version 8.0.0 or above\nUpgrade to upcoming  FortiProxy version 7.6.7 or above\nFortinet remediated this issue in FortiSASE version 26.2.2 (not released) and hence customers do not need to perform any action."}]}},"cveMetadata":{"assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","assignerShortName":"fortinet","cveId":"CVE-2026-84393","datePublished":"2026-09-08T16:41:49.203Z","dateReserved":"2026-09-01T16:36:14.802Z","dateUpdated":"2026-09-10T03:56:52.472Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 17:18:37","lastModifiedDate":"2026-09-10 04:18:18","problem_types":["CWE-297","CWE-297 Information disclosure"],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-09T00:00:00+00:00","id":"CVE-2026-84393","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"84393","Ordinal":"1","Title":"CVE-2026-84393","CVE":"CVE-2026-84393","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"84393","Ordinal":"1","NoteData":"A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>","Type":"Description","Title":"CVE-2026-84393"}]}}}