[KEV] CVE-2025-68686 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2025-68686 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2025-68686 is a sensitive-information exposure vulnerability in Fortinet FortiOS that can be reached through crafted HTTP requests.
Technical Detail
The flaw may allow a remote unauthenticated attacker to bypass a patch intended to address a symbolic-link persistence mechanism observed in post-exploitation activity. Exploitation requires that the attacker has already compromised the FortiOS appliance through another vulnerability and obtained filesystem-level access. Successful exploitation may enable the attacker to retain or restore persistence and access sensitive information through the affected mechanism.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation methods are sufficiently developed for practical use by attackers. CISA has confirmed active exploitation in the wild, and the vulnerability was added to the Known Exploited Vulnerabilities catalog on July 27, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Apply Fortinet security updates for FortiOS as a priority and verify that affected appliances are running a version that includes the vendor’s remediation. Under CISA binding directive requirements, patch by August 17, 2026, or apply mitigations. Because exploitation requires prior filesystem-level compromise, investigate affected devices for unauthorized symbolic links, unexpected filesystem changes, suspicious administrative activity, and crafted or unusual HTTP requests. Review appliance logs and configuration integrity, rotate potentially exposed credentials, and rebuild or restore appliances from known-good images if evidence of prior compromise is identified.