> ZTNA Portal Improper Certificate Validation
[DATE: 08/09/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
7.3
An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website.
Revised on 2026-09-08 00:00:00