Skip to content
COOEY

EXPOSURES › CVE-2025-68686

CVE-2025-68686

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-27 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-68686 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A bypass vulnerability in FortiOS allows attackers to access sensitive information after initial compromise, circumventing previous patches and requiring immediate action for DIB organizations using the product.

FortiOS contains a vulnerability allowing unauthorized access to sensitive information, bypassing previous patches by exploiting a symbolic link persistence mechanism. DIB organizations using FortiOS must verify patching status and review existing security posture, as this vulnerability requires prior compromise. Failure to address this poses a significant compliance risk under CMMC and NIST 800-171.

Shame score — The vulnerability's existence despite previous patches demonstrates a recurring failure to adequately secure FortiOS, increasing the risk of data exposure and compliance violations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.