CVE-2025-68686

Published Feb 10, 2026

Last updated a month ago

Exploit knownCVSS medium 5.9
Fortinet FortiOS
FortiOS
IoT
HTTP
Network
Tunneling protocol
SSL

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-68686 is an information disclosure vulnerability affecting multiple versions of Fortinet FortiOS, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200). This flaw allows a remote, unauthenticated attacker to bypass a previously implemented patch designed to address a symbolic link persistency mechanism. The bypass is achieved through specially crafted HTTP requests, which can lead to the exposure of sensitive data. It is important to note that CVE-2025-68686 acts as a secondary exploitation vector. For this vulnerability to be leveraged, the FortiOS product must have already been compromised at the filesystem level through a separate, prior vulnerability. This means the vulnerability extends the impact of previous compromises by allowing attackers to maintain unauthorized access to sensitive information on already affected FortiOS devices.

Description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Source
psirt@fortinet.com
NVD status
Analyzed
Products
fortios

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.9
Impact score
3.6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Exploit added on
Jul 27, 2026
Exploit action due
Aug 10, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@fortinet.com
CWE-200

Social media

Hype score
Not currently trending
  1. CVSS 5.9 なので深刻度だけ見ると後回しになりますが、CVE-2025-68686 は KEV 収載済みで是正期限も過ぎています。実際に悪用されている FortiOS の穴です。スコアで足切りすると落ちる型なので、KEV 収載の有無を別

    @Joe_Biden_ja

    19 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA’s Aug. 10 deadlines for exploited LoadMaster CVE-2026-8037 and FortiOS CVE-2025-68686 have passed. Any exception now needs owner escalation, a fixed remediation date, and compromise assessment—not a version check alone. https://t.co/QIjjY5STN3

    @isectech_

    11 Aug 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA KEV due today: FortiOS CVE-2025-68686. SSL-VPN info-disclosure bypasses a prior symlink-persistence fix after filesystem compromise. Patch: 7.6.2+ or 7.4.7+ (migrate 7.2/7.0/6.4). Never enabled SSL-VPN? Not impacted. https://t.co/RfH4oZfBmE

    @snypet86

    10 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔴 CVE-2025-68686 is actively exploited • Check affected versions • Validate SSL-VPN exposure 👉 Partner with Digital Warfare today and discover why organizations trust us identify CVE exposure. Read more: https://t.co/o4AA0BlUCc https://t.co/mXUORBGHae

    @Digital_Warfare

    10 Aug 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-68686: a CVSS 5.9 info-disclosure bug CISA still KEV-listed, deadline today. Bypasses Fortinet's fix for the 2025 SSL-VPN symlink trick — read-only FortiGate filesystem access that outlived patching the way in. 7.2/7.0/6.4: no fix. https://t.co/8JRc0yN7Tb

    @hellorecon

    10 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. FortiOS SSL-VPN-Lücke CVE-2025-68686 wird ausgenutzt https://t.co/7nSrEbERKt

    @ItE2u

    7 Aug 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🛡️ CISA le puso fecha límite al 10 de agosto para que las agencias federales de Estados Unidos parchen una falla de FortiOS que ya está bajo explotación activa. CVE-2025-68686 es un problema de exposición de información sensible que permite a un atacante remoto sortear

    @Soy_Nube_Negra

    7 Aug 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CISA KEV — Patch by these August 2026 deadlines: 🔴 CVE-2026-18577 | N-able N-central | CVSS 8.2 Auth bypass (incomplete fix for CVE-2026-18556) → admin takeover. Actively exploited. 📅 Due Aug 6 🟡 CVE-2025-68686 | Fortinet FortiOS | CVSS 5.9 Bypasses SSL-VPN

    @techepages

    4 Aug 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA KEV 警告 26/07/27:Fortinet FortiOS の脆弱性 CVE-2025-68686 を KEV に登録 https://t.co/sGAh99gT1Y Fortinet FortiOS の CVE-2025-68686 が、CISA KEV

    @iototsecnews

    4 Aug 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. DEEP DIVE — CVE-2025-68686 is CISA KEV-listed with an Aug 10 deadline and Fortinet scores it 5.3. Both are right. It is a patch bypass that only pays off on FortiGates already backdoored, so upgrading closes the read path and leaves the stolen credentials valid. https://t.co/HD

    @DailyCVEBrief

    3 Aug 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. 🛡️ CISA added CVE-2025-68686 affecting Fortinet FortiOS to its Known Exploited Vulnerabilities catalog after evidence of real-world exploitation. Source: CISA #Fortinet #FortiOS #PatchManagement

    @XQOPTRX

    3 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🔒 CISA marcó como explotada activamente la CVE-2025-68686 en Fortinet FortiOS, el sistema operativo detrás de los firewalls FortiGate y buena parte del stack de seguridad de Fortinet. La falla, clasificada como exposición de información (CWE-200), permite a un atacante

    @Soy_Nube_Negra

    3 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Fortinet FortiOS: SSL-VPN Patch-Bypass aktiv ausgenutzt CISA hat CVE-2025-68686 in den KEV-Katalog aufgenommen. Angreifer umgehen einen https://t.co/FvZBsLGMd8 https://t.co/wLzrVQr5X7

    @schoenfelderED

    31 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Attackers are already using CVE-2025-68686. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortin… Risk 45/100 · CVSS 5.9. Don't wait for the maintenance window on this. https://t.co/nbQ0UL6qvh #KEV #Fortinet #Infosec

    @BytesNora

    30 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 CVE-of-the-Day: CVE-2025-68686 — Fortinet FortiOS symbolic link patch bypass. FortiOS is the security-hardened OS running on all FortiGate n/w security platforms. A high confidentiality impact and a secondary exploitation vector that extends blast radius of prior compromi

    @YourDailyCVE

    29 Jul 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. Fortinet FortiOS au KEV : exploitation active selon la CISA (CVE-2025-68686). Art. 14 du CRA : signalement sous 24 h. Exposés ? #infosec #CRA

    @libtracker_io

    29 Jul 2026

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CISA added Fortinet CVE-2025-68686 to its exploited-vulnerabilities list on 27 Jul 2026. It is a persistence bypass, so if a FortiGate was compromised earlier, patching may not have evicted the attacker. Upgrade, then hunt. https://t.co/0GXnPhtFXw https://t.co/jjQg69lp17

    @CyberPulse_aus

    29 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🔐 Daily Security & Standards Brief (Jul 28) CVE-2025-68686--Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor: patch Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor and verify the fix held. Full digest 👇--PCMedicalis

    @PCMedicalist

    29 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. PCMedicalist Signal · Jul 28 CVE-2025-68686--Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor: patch Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor and verify the fix held. Full brief 👇 #CyberSecurity #Vulnerability http

    @PCMedicalist

    28 Jul 2026

    25 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Warning: #CISA added #CVE-2025-68686 in #Fortinet #FortiOS to its #KEV list, indicating active exploitation. The vulnerability was disclosed in February 2026. If you haven't patched, it's time to #Patch #Patch #Patch!

    @CCBalert

    28 Jul 2026

    462 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Security Bulletin: SSL-VPN Symlink Persistence Patch Bypass in FortiOS - FortiOS SSL-VPN vulnerability (CVE-2025-68686) allows attackers to bypass a persistence patch on previously compromised devices. Actively exploited and listed in CISA KEV. https://t.co/QHgDDQ0tfi

    @RedLegg

    28 Jul 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CISA adds CVE-2026-16812 in Arista VeloCloud Orchestrator and CVE-2025-68686 in FortiOS to its KEV catalog after confirming active exploitation.

    @WorldCyberNewsX

    28 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. [KEV Alert] CVE-2025-68686: FortiOS Symbolic Link Patch Bypass Restores Post-Exploit Persistence on OT Perimeter Firewalls https://t.co/pTxfWZzieL #ICS #OTSecurity #SCADA #CriticalInfrastructure

    @breachspider

    28 Jul 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CISA has added Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Organizations using FortiGate firewalls should apply patches immediately to prevent unauthorized access and potential data breaches. https:

    @dailytechonx

    28 Jul 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. ❗️GoogleがClaude AIの共有チャットをインデックス、一時的に検索結果に表示 🚨FortiOS、VeloCloud Orchestratorの脆弱性が攻撃で悪用される:米CISAがKEVカタログに追加(CVE-2025-68686、CVE-2026-16812) 〜サイバーアラー

    @MachinaRecord

    28 Jul 2026

    185 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Jul 27) CVE-2025-68686 Fortinet FortiOSにおける機密情報の不正アクセス脆弱性 CVE-2026-16812 Arista VeloCloud Orchestrator オ

    @foxbook

    28 Jul 2026

    360 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  27. 🔒 #CyberSecurity CVE-2025-68686 & CVE-2026-16812: CISA KEV Alert — FortiOS and VeloCloud Critica… "CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/wp10iYMnJQ #CyberSecurity #ThreatIntel #cve #zeroday #p

    @SecurityAr58409

    28 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🔐 Daily Security & Standards Brief (Jul 27) CVE-2025-68686--Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor: patch Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor and verify the fix held. Full digest 👇--PCMedicalis

    @PCMedicalist

    28 Jul 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🔒 #CyberSecurity CVE-2025-68686: Fortinet FortiOS Symlink Bypass — Detection and Remediation "On July 27, 2026, CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/PYYVU75N2g #CyberSecurity #ThreatIntel #cve202568686 #critical #ci

    @SecurityAr58409

    28 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 CISA has added two actively exploited flaws to its KEV catalogue: • CVE-2026-16812 — Arista VeloCloud Orchestrator command injection • CVE-2025-68686 — FortiOS SSL-VPN vulnerability Treat both as emergency patch priorities. #CISA #CVE #BlueTeam Source: CISA, 27 Ju

    @XQOPTRX

    28 Jul 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 米当局、「FortiOS」「VeloCloud Orchestrator」の脆弱性悪用を確認:Security NEXT https://t.co/Qj5ET5gu67 "CISAは現地時間2026年7月27日、「悪用が確認された脆弱性カタログ(KEV)」へ2件の脆弱性「CVE-2026-16812」「CVE-2025-68686」

    @catnap707

    27 Jul 2026

    158 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  32. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、FortiOSのCVE-2025-68686とアリスタ社VeloCloud Orchestratorオンプレミス版のCVE-2026-16812を追加。対処期限はFortiOSが8/10、VeloClou

    @__kokumoto

    27 Jul 2026

    1023 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    2 Replies

    0 Quotes

  33. CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now. #CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity https://t.co/y0zA64sZdu

    @Daily_CyberSec

    27 Jul 2026

    372 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  34. Fortinet has patched an actively exploited vulnerability in FortiOS (CVE-2025-68686). Affected versions: • FortiOS 7.6.0 – 7.6.1 • FortiOS 7.4.0 – 7.4.6 • and earlier affected releases The issue is a sensitive information exposure flaw. A remote unauthenticated a

    @CyberWatch05

    27 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. ⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-07-27 CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVSS 5.9 · EPSS 0.5% · 7 public exploits Details, versions & intel → https://t.co/UK7lgTZg4K https://t.c

    @notCVE

    27 Jul 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🛡️We added Fortinet FortiOS vulnerability CVE-2025-68686 and Arista Networks VeloCloud Orchestrator On-Prem CVE-2026-16812 to our KEV Catalog. Visit https://t.co/2EEdX3edvs & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/QV

    @CISACyber

    27 Jul 2026

    7842 Impressions

    19 Retweets

    31 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  37. Fortinet has disclosed CVE-2025-68686, an information disclosure vulnerability affecting multiple FortiOS versions. An unauthenticated attacker who has already gained filesystem-level access through another vulnerability may be able to bypass Fortinet's symbolic link persistence

    @geovexintel

    27 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. استغلال ثغرات أمنية في أجهزة FortiGate لإنشاء روابط رمزية خبيثة تمنح المهاجمين وصولاً مستمراً للقراءة فقط إلى ملفات النظام، حتى بعد سد ثغرات الاختراق، وفق @For

    @cyberscastx

    15 Mar 2026

    605 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  39. 『allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests.』 CVE-2025-68686 FortiOS SSL-VPN SSL-VPN Symlink Persistence Patch Bypass https://t.co/obE2kEzSJw

    @autumn_good_35

    13 Feb 2026

    305 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations