CVE-2025-68686Active Exploitation(fortinet / fortios)

CRITICALCVSS 5.9 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-200

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios

Threat summary

  • Active exploitation appears in 30 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 41 mentions across 17 observed days

What's happening

  • Active exploitation reported across 30 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 23 signals
  • Disclosure: 3 classified signals
  • Peaked 11d ago at 14 mentions (2026-07-28); latest day: 1
  • 41 total mentions across 17 days

Affected systems

Vendors
Products
fortios

Deep dive

Activity timeline41 mentions / 17d
0471114Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Mentions · 2026-02-13: 1Mentions · 2026-03-15: 1Mentions · 2026-07-27: 5Mentions · 2026-07-28: 14Mentions · 2026-07-29: 3Mentions · 2026-07-30: 1Mentions · 2026-08-03: 3Mentions · 2026-08-04: 2Mentions · 2026-08-07: 2Mentions · 2026-08-10: 2Mentions · 2026-08-11: 1Mentions · 2026-08-19: 1Mentions · 2026-09-10: 1Mentions · 2026-09-13: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-09-13: 1Exploit Tool / Code · 2026-02-11: 1Active Exploitation · 2026-07-27: 3Active Exploitation · 2026-07-28: 12Active Exploitation · 2026-07-29: 2Active Exploitation · 2026-07-30: 1Active Exploitation · 2026-08-03: 2Active Exploitation · 2026-08-04: 2Active Exploitation · 2026-08-07: 2Active Exploitation · 2026-08-10: 2Active Exploitation · 2026-08-11: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-09-13: 1Active Exploitation · 2026-09-23: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-07-27: 3Patch / Workaround · 2026-07-28: 7Patch / Workaround · 2026-07-29: 2Patch / Workaround · 2026-08-03: 2Patch / Workaround · 2026-08-04: 2Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-02-13: 1Technical Details · 2026-03-15: 1Technical Details · 2026-07-27: 2Technical Details · 2026-07-28: 8Technical Details · 2026-07-29: 2Technical Details · 2026-07-30: 1Technical Details · 2026-08-03: 2Technical Details · 2026-08-04: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-19: 1Technical Details · 2026-09-10: 1Technical Details · 2026-09-23: 102-1002-1102-1303-1507-2707-2807-2907-3008-0308-0408-0708-1008-1108-1909-1009-1309-23
Signal classification5 categories
Active Exploitation
2765.9%
Patch
717.1%
Disclosure
37.3%
General
37.3%
PoC
12.4%
Referenced assets30 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-101
Patch1
2026-02-111
PoC1
2026-02-131
Disclosure1
2026-03-151
Disclosure1
2026-07-275
Active Exploitation3General1Patch1
2026-07-2814
Active Exploitation11Disclosure1Patch2
2026-07-293
Active Exploitation1Patch2
2026-07-301
Active Exploitation1
2026-08-033
Active Exploitation1General1Patch1
2026-08-042
Active Exploitation2
2026-08-072
Active Exploitation2
2026-08-102
Active Exploitation2
2026-08-111
Active Exploitation1
2026-08-191
Active Exploitation1
2026-09-101
General1
2026-09-131
Active Exploitation1
2026-09-231
Active Exploitation1
Full discourse20 posts
  • Peter Gabaldon@PedroGabaldon
    PoC

    Today I am releasing the details about the FortiGate Symlink persistence method. The patch could be byppassed and Fortinet has now fixed that: https://labs.itresit.es/2026/02/11/fortigate-symlink-persistence-method-patch-bypass-cve-2025-68686/ PSIRT: https://www.fortiguard.com/psirt/FG-IR-25-934 Tool here: https://github.com/I3IT/Fortigate.Symlink.Persistence.Checker https://pgj11.com/posts/FortiGate-Symlink-Attack/

    Post summary

    The author discloses details about a FortiGate Symlink persistence vulnerability, provides a GitHub tool and blog post as proof‑of‑concept references, and notes that Fortinet has applied a fix.

    215041233.6K
    577 followersView on X
  • CISA Cyber@CISACyber
    General

    🛡️We added Fortinet FortiOS vulnerability CVE-2025-68686 and Arista Networks VeloCloud Orchestrator On-Prem CVE-2026-16812 to our KEV Catalog. Visit http://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/QVcUhjwn0z

    Post summary

    The tweet announces that two CVEs were added to a KEV catalog and urges organizations to apply mitigations, but provides no PoC, exploit details, or active exploitation evidence.

    12403789.4K
    302.4K followersView on X
  • سايبركاست@cyberscastx
    Disclosure

    استغلال ثغرات أمنية في أجهزة FortiGate لإنشاء روابط رمزية خبيثة تمنح المهاجمين وصولاً مستمراً للقراءة فقط إلى ملفات النظام، حتى بعد سد ثغرات الاختراق، وفق @Fortinet تمكن الثغرة CVE-2025-68686 المهاجم من الإبقاء على وصول للقراءة فقط عبر مكون SSL-VPN من خلال رابط رمزي خبيث. https://t.co/5vxg0NZhvJ

    Post summary

    The tweet announces a new Fortinet FortiGate vulnerability (CVE‑2025‑68686) that allows attackers to maintain read‑only access via malicious symbolic links in the SSL‑VPN component, even after patching.

    12032882
    6.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests.』 CVE-2025-68686 FortiOS SSL-VPN SSL-VPN Symlink Persistence Patch Bypass https://www.fortiguard.com/psirt/FG-IR-25-934

    Post summary

    CVE-2025-68686 enables a remote unauthenticated attacker to bypass a FortiOS SSL‑VPN patch for symbolic link persistence using crafted HTTP requests, as disclosed by FortiGuard.

    10030428
    6.7K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: #CISA added #CVE-2025-68686 in #Fortinet #FortiOS to its #KEV list, indicating active exploitation. The vulnerability was disclosed in February 2026. If you haven't patched, it's time to #Patch #Patch #Patch!

    Post summary

    CISA listed CVE-2025-68686 for Fortinet FortiOS in its KEV list, indicating that active exploitation is occurring, and users are urged to patch immediately.

    02000613
    7.2K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Jul 27) CVE-2025-68686 Fortinet FortiOSにおける機密情報の不正アクセス脆弱性 CVE-2026-16812 Arista VeloCloud Orchestrator オンプレミス OS コマンドインジェクションの脆弱性 https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has announced that two CVEs are actively exploited, adding them to its catalog. The alert confirms ongoing real‑world attacks against Fortinet FortiOS and Arista VeloCloud Orchestrator.

    00011376
    4.9K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Active Exploitation

    米当局、「FortiOS」「VeloCloud Orchestrator」の脆弱性悪用を確認:Security NEXT https://www.security-next.com/187925 "CISAは現地時間2026年7月27日、「悪用が確認された脆弱性カタログ(KEV)」へ2件の脆弱性「CVE-2026-16812」「CVE-2025-68686」を追加した"

    Post summary

    CISA confirmed that CVE-2026-16812 and CVE-2025-68686 have been actively exploited, but the post provides no PoC, exploit code, patch, or detailed technical information.

    00011173
    3.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now. #CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity http://securityonline.info/cisa-kev-arista-velocloud-fortios/

    Post summary

    CISA KEV alerts that two vulnerabilities—Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686—are actively exploited in the wild and urges immediate patching.

    00011402
    12.6K followersView on X
  • CVE Brief@DailyCVEBrief
    Patch

    DEEP DIVE — CVE-2025-68686 is CISA KEV-listed with an Aug 10 deadline and Fortinet scores it 5.3. Both are right. It is a patch bypass that only pays off on FortiGates already backdoored, so upgrading closes the read path and leaves the stolen credentials valid. https://t.co/HDg4q2atuF

    Post summary

    CVE-2025-68686 is a CISA KEV-listed exploitation that functions as a patch bypass on already compromised Fortinet devices; upgrading removes the read path and mitigates the risk.

    1000057
    25 followersView on X
  • NotCVE@notCVE
    Active Exploitation

    ⚠️ New in CISA KEV this week — exploited in the wild: • Arista VeloCloud Orchestrator… — CVSS 10 https://notcve.org/cve/CVE-2026-16812 • Fortinet FortiOS Exposure of… — CVSS 5.9 https://notcve.org/cve/CVE-2025-68686 • Cisco Secure Firewall Management… — CVSS 5.3 https://notcve.org/cve/CVE-2026-20316

    Post summary

    Three CVEs are highlighted as newly added to CISA KEV and actively exploited in the wild, with CVSS scores listed, but no PoC, exploit tool, or patch details are provided.

    1000076
    62 followersView on X
  • Frontiera Tech@FrontieraTechIT
    Patch

    🛡️ BOLLETTINO CYBER | 29/07/2026 1. Vulnerabilità critica in JetBrains TeamCity (CVE-2026-63077) Rilevata una vulnerabilità critica di autenticazione bypass e remote code execution non autenticata. Un attaccante con accesso HTTP(S) al server può eseguire comandi arbitrari con i privilegi del processo TeamCity. Aggiornare immediatamente alle versioni 2025.11.7 o 2026.1.3. 2. Microsoft Patch Tuesday: 622 vulnerabilità, due 0-day già sfruttate Gli aggiornamenti di luglio risolvono un record di 622 CVE, tra cui due zero-day con sfruttamento attivo in the wild (SharePoint e Active Directory Federation Services). Priorità massima all’installazione delle patch. 3. Fortinet FortiOS: sfruttamento attivo di CVE-2025-68686 CISA ha inserito nel catalogo KEV e CSIRT Italia ha segnalato lo sfruttamento in rete di questa vulnerabilità di information disclosure in FortiOS. Consente a un attaccante non autenticato di accedere a informazioni sensibili. Aggiornare subito i dispositivi esposti. #Cybersecurity #CyberItalia #InfoSec #ACN #ENISA

    Post summary

    The bulletin reports several critical CVEs, lists immediate patch versions, and notes that some are currently being exploited in the wild.

    1000072
    42 followersView on X
  • LibTracker@libtracker_io
    Active Exploitation

    Fortinet FortiOS au KEV : exploitation active selon la CISA (CVE-2025-68686). Art. 14 du CRA : signalement sous 24 h. Exposés ? #infosec #CRA

    Post summary

    The post announces that CVE-2025-68686 is being actively exploited, as reported by CISA, underscoring the urgency of reporting within 24 hours under Article 14 of the CRA.

    0001053
    1 followersView on X
  • PCMedicalist@PCMedicalist
    Patch

    PCMedicalist Signal · Jul 28 CVE-2025-68686--Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor: patch Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor and verify the fix held. Full brief 👇 #CyberSecurity #Vulnerability #Fortinet PCMedicalist · http://pcmedicalist.com/intel

    Post summary

    The post announces that Fortinet FortiOS CVE-2025-68686, an information exposure vulnerability, has been patched and the fix verified.

    0001029
    126 followersView on X
  • PCMedicalist@PCMedicalist
    Disclosure

    PCMedicalist Signal · Jul 28 CVE-2025-68686 is now in CISA KEV--Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor, a privileged function with no auth in front of it. We've built agent systems and on-chain infrastructure on Blue-Team discipline for 17 years. Whether it's a PCMedicalist dApp on Base or the MCINTOSHI stack consolidating into the same infrastructure, the boundary is drawn before the first endpoint exists--not discovered after a KEV drop. "Internal" was never a control. It's a habit. We break it at the architecture layer. #GovTech #Vulnerability #Fortinet PCMedicalist · http://pcmedicalist.com/intel

    Post summary

    The post announces that CVE‑2025‑68686 has been added to the CISA KEV list, indicating a serious vulnerability involving a privileged function without authentication, but no PoC, exploit, or patch details are provided.

    0001024
    126 followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 28/07/2026 Three relevant updates for today: 1. CISA adds two actively exploited vulnerabilities to the KEV catalog CISA has added a maximum-severity OS command injection in Arista VeloCloud Orchestrator (CVE-2026-16812, CVSS 10.0) and a Fortinet FortiOS information disclosure flaw (CVE-2025-68686). Both are under active exploitation. Federal agencies must prioritize remediation — especially for internet-facing instances — as these grant attackers deep access into network orchestration and edge devices. 2. Unpatched FastJson RCE actively hitting US organizations Hackers are exploiting CVE-2026-16723 in FastJson 1.2.68–1.2.83, enabling unauthenticated remote code execution in common Spring Boot fat-JAR deployments. Attacks are almost exclusively targeting US firms across finance, healthcare, retail and tech. No official patch exists for the 1.x branch — switch to SafeMode or migrate to FastJson 2.x immediately. 3. Critical unauthenticated RCE in JetBrains TeamCity On-Premises CVE-2026-63077 (CVSS 9.8) allows remote attackers to bypass authentication and execute OS commands on any TeamCity server reachable over HTTP(S). All on-premises versions are affected. JetBrains has released patches (2025.11.7 / 2026.1.3) and a plugin for older builds. CI/CD servers remain high-value targets — restrict exposure and patch today. #Cybersecurity #InfoSec #CISA #ThreatIntel #NIST

    Post summary

    The bulletin highlights multiple CVEs that are actively being exploited in the wild, with vendor advisories and patches recommended to mitigate the threats.

    1000060
    42 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    ❗️GoogleがClaude AIの共有チャットをインデックス、一時的に検索結果に表示 🚨FortiOS、VeloCloud Orchestratorの脆弱性が攻撃で悪用される:米CISAがKEVカタログに追加(CVE-2025-68686、CVE-2026-16812) 〜サイバーアラート7月28日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46887/

    Post summary

    The post reports that FortiOS and VeloCloud Orchestrator vulnerabilities (CVE-2025-68686, CVE-2026-16812) are actively exploited and have been added to the US CISA KEV catalog, though no PoC, exploit code, patch, or technical details are provided.

    00010197
    1.3K followersView on X
  • hi^^@collysucker
    Patch

    https://www.fortiguard.com/psirt/FG-IR-25-934 FortiGate SSLVPN vuln CVE-2025-68686 (Not) rated highly yet. However, I would promptly patch it (and quickly move away from SSL VPN, regardless of the vendor; instead use IKEv2 EAP-TLS or WireGuard). I think this one might rapidly elevate to a RCE

    Post summary

    FortiGate SSLVPN vulnerability CVE-2025-68686 is highlighted with a recommendation for immediate patching and discontinuation of SSL VPN usage, anticipating possible RCE escalation.

    10000172
    220 followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Una @CISACyber

    Post summary

    The announcement highlights that CISA has added CVE-2025-68686 to the Known Exploited Vulnerabilities Catalog due to evidence of active exploitation, emphasizing the threat's real-world usage.

    0000061
    1.5K followersView on X
  • System Force I.T.@systemforce
    Active Exploitation

    CISA’s Known Exploited Vulnerabilities catalogue, the official US government list of flaws being actively targeted by attackers, was updated at the end of July to include CVE-2025-68686, a vulnerability in Fortinet’s FortiOS software that powers https://systemforce.co.uk/blog/2026/09/13/fortinet-ssl-vpn-patch-bypass-cve-2025-68686/ https://t.co/8jo0umluYt

    Post summary

    CISA added CVE-2025-68686, a FortiOS flaw, to its Known Exploited Vulnerabilities list, confirming it is being actively targeted in the wild.

    0000083
    3.0K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2025-68686: FortiOS Symbolic Link Patch Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04xb0-y0

    Post summary

    The text identifies CVE‑2025‑68686 and hints at its technical nature, but it does not provide evidence of a PoC, exploit, active attacks, or a patch—making it a general mention about the vulnerability.

    0000029
    35 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---

Explore more