Cyber Resilience
← All news

KEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)

Our takeCISA added CVE-2025-68686 to KEV. It lets a remote unauthenticated attacker bypass a prior FortiOS symbolic-link patch via crafted HTTP requests, but only after filesystem-level compromise via another flaw. Patch if you run FortiOS yourself.
Sources (8)
What this means for you — Security leader:If FortiOS is in your estate, treat CVE-2025-68686 as a KEV item and patch to Fortinet’s fixed builds on the CISA deadline. Note the attacker needs a prior filesystem-level compromise; still prioritize because it defeats a post-exploit patch for symbolic-link persistency.
What this means for you — Lean IT orgs:If you run a FortiGate or other FortiOS device, apply the vendor update now. You do not need a security team for this—use Fortinet’s fixed version list and your usual firmware upgrade path.
What this means for you — MSP:Inventory every client FortiOS/FortiGate instance, map versions against Fortinet’s fixed builds, and schedule upgrades under the KEV window. Flag any appliance already known compromised or left on unsupported builds.
What this means for you — Researcher:Post-exploit info-exposure that bypasses the symbolic-link persistency patch via crafted HTTP after filesystem compromise. Useful for chaining notes and for checking whether residual symlink/persist techniques still work on unpatched FortiOS.