CVE-2026-25815Active Exploitation

LOWCVSS 3.2 · LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option that eliminates the weakness. However, that non-default option can disrupt functionality as shown in the "Managing FortiGates with private data encryption" document, and is therefore intentionally not a default option.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1394

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-05: 2Mentions · 2026-02-06: 1Active Exploitation · 2026-02-05: 1Technical Details · 2026-02-05: 202-0502-06
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-052
Active Exploitation1Disclosure1
2026-02-061
General1
Full discourse3 posts
  • CVE@CVEnew
    Active Exploitation

    CVE-2026-25815 Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 202… https://www.cve.org/CVERecord?id=CVE-2026-25815

    Post summary

    Fortinet FortiOS users (v7.6.6 and earlier) are being targeted by CVE‑2026‑25815, which lets attackers decrypt LDAP credentials stored in configuration files; the vulnerability is actively exploited in the wild.

    00010297
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25815 Fortinet FortiOS LDAP Credential Decryption Vulnerability Through 7.6.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25815

    Post summary

    The snippet merely references CVE-2026-25815 with a title and a link, lacking any substantive detail on the vulnerability or its exploitation.

    0000094
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    📝 CVE-2026-25815: Fortinet (CVSS: 3.2)... Default shared encryption keys across FortiOS installations is a classic security anti-pattern—attackers can trivially ... https://zerodaysignal.com/vulnerability/CVE-2026-25815 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses CVE-2026-25815, explaining that FortiOS uses default shared encryption keys, rating CVSS 3.2, but does not provide a PoC, exploit, or patch.

    0000092
    132 followersView on X

Explore more