← back
CVE-2026-84388criticalCWE-1021

CVE-2026-84388

45Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.1
from disclosure to weapon0 days
Published on NVDSep 22
1st PoCSep 22
exploitation probability
observed exploitation
nono source reports it
1 public exploit(s)
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L/E:P/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.