THREAT OPS › CVEs › CVE-2025-68686
CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Vulnerability details
- Affected productsFortiOS
- KEV remediation due2026-08-10
Related reporting
- July 2026 CVE Landscaperecordedfuture
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories
- Fortinet security advisory (AV26-109) – Update 1cccs_ca
- [CISA KEV] CVE-2025-68686 — Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerabilitycisa_kev