Fortinet patches critical FortiMonitorOnSight and Privileged Access Agent flaws including CVE-2026-84390 and CVE-2026-84388

Fortinet released fixes for two critical security flaws that could let attackers break into monitoring systems or abuse a browser extension to route a victim’s web traffic. CVE-2026-84390 (CVSS 9.6) affects the FortiMonitorOnSight web portal and allows unauthenticated authentication bypass through forged or reused JSON Web Tokens (JWTs). CVE-2026-84388 (CVSS 9.1) affects the Fortinet Privileged Access Agent Chrome extension and can let a remote attacker proxy browser traffic if a user visits a malicious site; full remediation requires FortiPAM 1.9.1 or 1.8.4 plus extension version 8.0.1.123 or later.
Why it matters: Organizations using these Fortinet products could face silent account bypass or browser-session abuse from remote attackers. This is an update-now story: admins should patch affected Fortinet components and verify the Chrome extension and FortiPAM versions together, because one fix alone is not sufficient for the extension-related issue.

Sources

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Ionut Arghire 2026.09.09 100% relevant
This article appears to be the first item here establishing the specific September 2026 Fortinet patch event for CVE-2026-84390 in FortiMonitorOnSight and CVE-2026-84388 in the Fortinet Privileged Access Agent Chrome extension.
← Back to all stories