CVE-2025-68686
Fortinet FortiOS: Exposure of Sensitive Information to an Unauthorized Actor
As of , CVE-2025-68686 in Fortinet FortiOS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.
- Exploited
- Yes: CISA listed it on 27 July 2026
- US federal deadline
- 10 August 202614 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.30Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: fortiguard.fortinet.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA's required action
What the flaw is
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CISA's description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
The CVE record's description, from fortinet
- CVE published
- 10 February 2026
- Assigned by
- fortinet
- CVSS
- 5.3 Medium (CVSS 3.1, from the CNA)
- CWE-200
- Exposure of Sensitive Information to an Unauthorized Actor
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
FortiOS: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2018-13379SSL VPN Path Traversal | Fortinet FortiOS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2024-21762Out-of-Bound Write | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.83 | 0.83 | ||
| CVE-2022-42475Heap-Based Buffer Overflow | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| CVE-2020-12812SSL VPN Improper Authentication | Fortinet FortiOS | Patch this weekRansomware use | 0.45 | ||
| CVE-2019-5591Default Configuration | Fortinet FortiOS | Patch this weekRansomware use | 0.18 | ||
| CVE-2019-6693Use of Hard-Coded Credentials | Fortinet FortiOS | Patch this weekRansomware use | 0.06 | ||
| CVE-2022-41328Path Traversal | Fortinet FortiOS | Patch soon | 0.11 | ||
| CVE-2021-44168Arbitrary File Download | Fortinet FortiOS | Patch soon | 0.01 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org