CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog on 2026-07-27, confirming active exploitation of a FortiOS flaw that lets attackers restore symbolic-link persistence Fortinet had previously patched out.
What Is It
CVE-2025-68686 is an Exposure of Sensitive Information to an Unauthorized Actor vulnerability (CWE-200) in Fortinet FortiOS. Per Fortinet's PSIRT advisory and the NVD record, a remote unauthenticated attacker can bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, using crafted HTTP requests.
The critical caveat is in the vendor description itself: an attacker would need to have already compromised the device via another vulnerability, at filesystem level. This is a persistence-recovery bug, not an initial access bug.
Why It Matters
Fortinet scores this CVSS 3.1 base 5.9 (MEDIUM), vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N, network-reachable, no privileges or user interaction required, high attack complexity, with high confidentiality impact and no integrity or availability impact.
A MEDIUM base score may not, on its own, capture how this bug is being used in the field. CISA's SSVC assessment marks exploitation as active, automatable as no, and technical impact as partial: that is, confirmed in-the-wild use, but not at scale and without full control of the target. Read alongside the vendor's note that prior device compromise is a prerequisite, the plausible concern is that defenders who applied the original symlink fix and assumed persistence was cleared may still be hosting attacker footholds on previously compromised appliances. That scenario is an inference from the exploitation status and the nature of the bug rather than something the advisories state directly, and the scale of any such residual access is not established in the published data. Known ransomware campaign use is listed as Unknown.
What's Vulnerable
The affected FortiOS versions listed in the advisory data are:
- 7.6.0 through 7.6.1
- 7.4.0 through 7.4.6
- 7.2; all versions (through 7.2.13)
- 7.0; all versions (through 7.0.19)
- 6.4; all versions (through 6.4.16)
Note a discrepancy in the published data: NVD's machine-readable configuration entry defines a single vulnerable range of 6.4.0 up to (but excluding) 7.4.7, which does not cover the 7.6.0–7.6.1 branch named in the version list. The 6.4.x, 7.0.x, 7.2.x, and 7.4.x entries are consistent with that range; 7.6.x is not. Until the CPE data is reconciled, treat Fortinet's PSIRT advisory (FG-IR-25-934) as authoritative for 7.6.x coverage and assume 7.6.0 and 7.6.1 are in scope rather than relying on the NVD range alone; automated triage keyed to NVD configuration data may silently pass 7.6.x appliances.
Patch Status
CISA's required action: apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
Due date: 2026-08-10. The CVE was published 2026-02-10 and last modified 2026-07-27; NVD status is Analyzed.
Sources
- Fortinet PSIRT FG-IR-25-934; https://fortiguard.fortinet.com/psirt/FG-IR-25-934
- NVD, CVE-2025-68686, https://nvd.nist.gov/vuln/detail/CVE-2025-68686
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk