SSL-VPN Reflected XSS

MonitorCVSS 6.1FG-IR-26-150Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A reflected cross-site scripting (XSS) vulnerability exists in the SSL-VPN portal of Fortinet FortiOS, FortiPAM, and FortiProxy. An attacker can inject malicious JavaScript into the portal by crafting a special URL. When a user clicks the malicious link, the JavaScript runs in their browser, potentially allowing the attacker to steal credentials or session tokens. The vulnerability affects FortiOS 7.6.0–7.6.6, all 7.4 and 7.2 versions; FortiPAM 1.8.0, all 1.7 and 1.6 versions; and FortiProxy 7.4.0–7.4.3 and 7.2.0–7.2.9. Patches are available for several product lines, though older branches require migration to newer versions.

What this means
What could happen
An attacker could inject malicious JavaScript into the SSL-VPN login portal, allowing them to steal administrator or user credentials or session tokens when a user visits a crafted link. This could lead to unauthorized access to the VPN and the systems it protects.
Who's at risk
Water authorities and utilities using Fortinet SSL-VPN (FortiOS, FortiPAM, or FortiProxy) for remote access to control systems are affected. This impacts any organization where engineers, operators, or IT staff use the VPN portal to access SCADA systems, PLCs, or other critical infrastructure remotely.
How it could be exploited
An attacker crafts a malicious URL with JavaScript payload embedded in a parameter that the SSL-VPN portal reflects back to the user's browser without sanitization. When an administrator or operator clicks the link, the browser executes the injected script, which can capture login credentials, steal session cookies, or perform actions on behalf of the user within the VPN portal.
Prerequisites
  • User must click on attacker-crafted link
  • SSL-VPN portal must be reachable from the internet
  • Vulnerable Fortinet product (FortiOS, FortiPAM, or FortiProxy) must be running an affected version
remotely exploitableno authentication requiredlow complexityactively exploited in the wild (evidence of practical exploitation)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
FortiOS7.6.0 - 7.6.67.6.7+
FortiOS7.4 all versionsMigrate to fixed release
FortiOS7.2 all versionsMigrate to fixed release
FortiPAM1.8.01.8.1+
FortiPAM1.7 all versionsMigrate to fixed release
FortiPAM1.6 all versions and 6 moreMigrate to fixed release
FortiProxy7.4.0 - 7.4.37.4.4+
FortiProxy7.2.0 - 7.2.97.2.10+
Remediation & Mitigation
0/6
Do now
0/1
HARDENINGEducate users and administrators to avoid clicking on untrusted links to the SSL-VPN portal, especially those received via email or chat
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

FortiOS
HOTFIXUpdate FortiOS to version 7.6.7 or later
HOTFIXMigrate FortiOS 7.4 and 7.2 installations to a fixed release (7.6.7 or later)
FortiPAM
HOTFIXUpdate FortiPAM to version 1.8.1 or later
HOTFIXMigrate FortiPAM 1.7 and 1.6 installations to a fixed release (1.8.1 or later)
FortiProxy
HOTFIXUpdate FortiProxy to version 7.4.4 or later (for 7.4.x branches) or 7.2.10 or later (for 7.2.x branches)
API: /api/v1/advisories/47214021-212f-4184-9d0d-c73651ec35de

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.