سايبركاست[verified]@cyberscastxDisclosure
The tweet announces a new Fortinet FortiGate vulnerability (CVE‑2025‑68686) that allows attackers to maintain read‑only access via malicious symbolic links in the SSL‑VPN component, even after patching.
キタきつね[verified]@foxbookActive Exploitation
CISA has announced that two CVEs are actively exploited, adding them to its catalog. The alert confirms ongoing real‑world attacks against Fortinet FortiOS and Arista VeloCloud Orchestrator.
CVE Brief[verified]@DailyCVEBriefPatch
CVE-2025-68686 is a CISA KEV-listed exploitation that functions as a patch bypass on already compromised Fortinet devices; upgrading removes the read path and mitigates the risk.
Frontiera Tech[verified]@FrontieraTechITPatch
The bulletin reports several critical CVEs, lists immediate patch versions, and notes that some are currently being exploited in the wild.
Frontiera Tech[verified]@FrontieraTechITActive Exploitation
The bulletin highlights multiple CVEs that are actively being exploited in the wild, with vendor advisories and patches recommended to mitigate the threats.
Machina Record[verified]@MachinaRecordActive Exploitation
The post reports that FortiOS and VeloCloud Orchestrator vulnerabilities (CVE-2025-68686, CVE-2026-16812) are actively exploited and have been added to the US CISA KEV catalog, though no PoC, exploit code, patch, or technical details are provided.
IntegSec[verified]@integ_secGeneral
The text identifies CVE‑2025‑68686 and hints at its technical nature, but it does not provide evidence of a PoC, exploit, active attacks, or a patch—making it a general mention about the vulnerability.
Peter Gabaldon@PedroGabaldonPoC
The author discloses details about a FortiGate Symlink persistence vulnerability, provides a GitHub tool and blog post as proof‑of‑concept references, and notes that Fortinet has applied a fix.