EXPOSURES › CVE-2025-68686
CVE-2025-68686
HIGH ⌖ ON CISA KEV · EXPLOITEDA bypass vulnerability in FortiOS allows attackers to access sensitive information after initial compromise, circumventing previous patches and requiring immediate action for DIB organizations using the product.
FortiOS contains a vulnerability allowing unauthorized access to sensitive information, bypassing previous patches by exploiting a symbolic link persistence mechanism. DIB organizations using FortiOS must verify patching status and review existing security posture, as this vulnerability requires prior compromise. Failure to address this poses a significant compliance risk under CMMC and NIST 800-171.
Shame score — The vulnerability's existence despite previous patches demonstrates a recurring failure to adequately secure FortiOS, increasing the risk of data exposure and compliance violations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.