CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a Fortinet FortiOS flaw that exposes sensitive information and lets a remote unauthenticated attacker bypass a patch for a symbolic-link persistence mechanism using crafted HTTP requests. The agency set an August 10, 2026 remediation deadline for Federal Civilian Executive Branch agencies and directed organizations to apply Fortinet mitigations and review devices for signs of earlier compromise.
Fortinet’s advisory says the issue affects FortiOS 7.4.0-7.4.3, 7.2.5-7.2.7, 7.0.12-7.0.14, and 6.4.13-6.4.16, while 7.6 is not affected, and recommends upgrading to 7.4.4+, 7.2.8+, or 7.0.15+, or migrating from 6.4 to a fixed release. The company described the bug as an improper access control weakness tied to bypassing real-time file system integrity checking write protection, and noted that exploitation requires the appliance to have already been compromised at the filesystem level through another vulnerability or method, making it a post-compromise persistence and patch-bypass risk rather than an initial access vector.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
KISA published a security notice urging users to apply Fortinet updates for CVE-2025-68686, an information exposure flaw in FortiOS. The notice identified affected FortiOS branches and listed fixed releases or required migration paths for unsupported branches.
CISA updated its Known Exploited Vulnerabilities catalog to add CVE-2025-68686, a Fortinet FortiOS flaw described as an exposure of sensitive information issue that can let a remote unauthenticated attacker bypass a patch for a symbolic-link persistence mechanism on already-compromised devices. The catalog release timestamp changed to 2026-07-27T17:00:05.7269Z and set a remediation due date of 2026-08-10 for the Fortinet entry.
A CVE record was published for CVE-2025-68686, describing a medium-severity Fortinet FortiOS information disclosure flaw that could let a remote unauthenticated attacker bypass a patch for the symbolic-link persistence mechanism using crafted HTTP requests. The record noted exploitation requires the device to have already been compromised at the filesystem level through another vulnerability.
Fortinet initially published PSIRT advisory FG-IR-24-012 for an improper access control vulnerability in FortiOS that can bypass real-time file system integrity checking write protection. The advisory said exploitation requires prior write access to the underlying system and recommended upgrading to fixed FortiOS versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourceacn.gov.it
Open sourcecve.org
Open sourcefortiguard.fortinet.com
Open sourcegov.br
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.