ON 27 July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2025‑68686 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Fortinet FortiOS and is named “Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability”.
It allows a remote unauthenticated attacker to bypass a previously‑applied patch for a symbolic‑link persistence mechanism via crafted HTTP requests, but only after the device has already been compromised at the filesystem level.
CVE‑2025‑68686 is an information‑exposure flaw that can be triggered over HTTP without authentication once an attacker has gained file‑system access to the FortiOS device. The vulnerability has a CVSS v3.1 base score of 5.3, rating it as Medium severity. A patch is available from Fortinet via advisory FG‑IR‑25‑934.
Active exploitation of this flaw has been observed in the wild, which is why it was placed in the KEV catalogue. No public ransomware campaign has been linked to CVE‑2025‑68686 at this time. CISA requires that Federal Civilian Executive Branch (FCEB) agencies apply the mitigations by 10 August 2026.
CISA directs FCEB agencies to apply mitigations in line with vendor instructions, ensuring compliance with BOD 26‑04 Prioritizing Security Updates Based on Risk and the Forensics Triage Requirements. Agencies must follow the BOD 26‑04 guidance for cloud services or discontinue use of FortiOS if mitigations cannot be applied. Stakeholders are responsible for evaluating each asset’s internet exposure and adhering to BOD 26‑04 patching guidelines. All other organisations should review their FortiOS deployments for exposure and apply the available patch promptly.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2025-68686 and the CISA KEV catalogue.