Fortinet’s Fixes Expose a Server-Client Trust Gap

Fortinet’s September 9 advisory covers 10 vulnerabilities across its Forti line, including critical bugs in FortiMonitorOnSight and the FortiPAM Chrome extension. NCSC-NL, INCIBE-CERT, and SecurityWeek all describe the two standouts as unauthenticated flaws that can either bypass login checks or route browser traffic through attacker-controlled servers. One flaw lets a remote attacker reuse or forge a JSON Web Token (JWT) so FortiMonitorOnSight accepts them as already authenticated. The other sits in the Fortinet Privileged Access Agent Chrome extension: if a user visits a malicious site, the extension can be made to send that browser traffic through attacker-controlled infrastructure. Fortinet says fixing the second issue requires coordinated updates to both FortiPAM and the extension. That coordination is the real takeaway for defenders. In estates that rely on browser extensions or agents in front of privileged web access, a server-only patch can leave the client path usable, and a client-only update can leave the backend trust break in place. The remaining Fortinet fixes matter too, but this advisory is chiefly a reminder that partial upgrades can preserve the control path an attacker needs.

Part of the PlainSec briefing for 2026-09-09

Every edition of this story: Fortinet’s Fixes Expose a Server-Client Trust Gap

Sources