PT-2026-88963 · Undefined · Undefined

CVE-2026-84388

·

Published

2026-09-09

·

Updated

2026-09-12

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
TL;DR. The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, allowed any site to set the browser's proxy for the session, alongside allowing any site to create a new tab and send screen recordings of it to an attacker's server. That makes for trivial phishing attacks which only require the user to view something sensitive in the attacker-opened tab. CVSS 9.1 | CVE-2026-84388 .
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-84388

Affected Products

Undefined