www.cisa.gov 7/28/2026, 8:46:29 AM · external

Fortinet FortiOS bug CVE-2025-68686 exposes data to hackers

Developing story vulnerability 1 article tracked
Arista VeloCloud Orchestrator zero‑day command injection exploited (CVE-2026-16812)
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog is maintained by CISA to assist organizations in managing vulnerabilities that are actively exploited in real-world attacks. It serves as a critical resource for cybersecurity professionals to prioritize their vulnerability management efforts. The current entry details the Fortinet FortiOS vulnerability (CVE-2025-68686) that exposes sensitive information to unauthorized actors, potentially allowing further attacks if the system was previously compromised. Recommendations include following vendor guidance for mitigations and adhering to CISA's directives for security updates.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline