CVE-2025-68686
KEVmassUnauthenticated Info-Exposure Bypass of Symlink Patch in Fortinet FortiOS
CISA: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2025-68686 is a sensitive-information-exposure flaw (CWE-200) in Fortinet FortiOS that allows a remote, unauthenticated attacker to bypass the vendor's patch for the symbolic-link (symlink) persistency mechanism seen in some post-exploitation cases. It is triggered by crafted HTTP requests sent to a device that has already been compromised through another vulnerability at the filesystem level, for example where symlinks were planted to maintain access to files. By bypassing the patch, the attacker can keep retrieving sensitive information from an otherwise remediated FortiGate device. Any organization running an affected FortiOS release is potentially affected; the CISA data does not enumerate specific versions, so administrators should consult Fortinet's advisory for the affected branches. The flaw was added to CISA's KEV catalog on 2026-07-27, confirming real-world exploitation, and EPSS assigns a 29.6% probability of exploitation within 30 days (98th percentile), with ransomware use currently unknown.
What to do: Patch affected FortiOS devices per Fortinet's current advisory, following BOD 26-04 timelines for federal agencies (apply mitigations per vendor instructions or discontinue use where mitigations are unavailable). Because this flaw defeats the earlier symlink-persistence fix, re-check previously remediated devices for residual or recreated symlinks and hunt for indicators of prior filesystem-level compromise, such as unexpected symlinks and anomalous SSL-VPN activity. Review logs for crafted HTTP requests and prioritize internet-facing FortiGate assets for patching and triage.
| Fortinet FortiOS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
- Affected
- Fortinet FortiOS
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Due date
- Ransomware use
- Unknown
- Vendors
- fortinet
- Products
- fortios
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N