ZeroDayAlert

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Fortinet FortiOS Added to KEV 2026-07-27 Federal due 2026-08-10 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Fortinet FortiOS deployments are affected by an information disclosure vulnerability that requires prior compromise through a separate vulnerability. The flaw allows a remote unauthenticated attacker to bypass a patch intended to address symbolic link persistence, but only after the device has already been compromised at the filesystem level. The record does not specify which versions of FortiOS are vulnerable.

How to check whether this touches you

  • Inventory your deployed Fortinet FortiOS instances, noting product type (FortiGate, FortiManager, etc.) and deployment context (on-premises, cloud-hosted, hybrid).
  • Determine whether any FortiOS device is reachable from the internet or from untrusted networks; this vulnerability requires prior compromise, so threat model depends on whether initial attack surface exists.
  • Review Fortinet's published advisory for affected version ranges and establish which versions are currently running on your assets; version fingerprinting via management interfaces or logs provides a starting signal, but backported security patches may affect your actual exposure.
  • Cross-check your asset inventory against any prior security incidents or intrusion attempts logged during the record's publish date and before, since exploitation presupposes earlier compromise.

What to do

  1. Apply the vendor mitigations published by Fortinet without delay, in accordance with CISA's BOD 26-04 guidance on prioritised patching; verify application and document the date and version applied.
  2. If immediate patching is not possible, isolate affected FortiOS devices from untrusted networks and reduce their internet reachability to the minimum operationally required.
  3. Review logs and filesystem activity on affected FortiOS instances from before the CVE publication date backwards for at least 90 days, looking for signs of prior compromise (unusual authentication, privilege escalation, or file modifications); log retention constraints often limit this window.
  4. If you identify evidence of prior compromise on any device, escalate to your incident response team and consider forensic acquisition before applying patches, since the vulnerability chain suggests active post-exploit activity may have occurred.

If you find you were exposed

Exploitation of this vulnerability requires prior compromise via a separate flaw, so any exposure almost certainly predates public disclosure of CVE-2025-68686. Review authentication logs, configuration change logs, and filesystem audit trails from your FortiOS devices for the preceding months to identify when initial compromise may have occurred. Your ability to hunt backwards depends heavily on log retention policies; most organisations retain FortiOS logs for 30–90 days by default, which may not reach back to the actual intrusion date.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2025-68686 is being exploited. It cannot tell you whether FortiOS is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →