DIRAS TAKE
Urgent — CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a mandated remediation date, so organisations with internet-facing FortiOS instances should prioritise risk assessment and apply vendor mitigations immediately.
What is CVE-2025-68686?
Remote unauthenticated actors can trigger exposure of sensitive information in Fortinet FortiOS (CVE-2025-68686). The flaw affects FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, 7.2.0–7.2.13, 7.0.0–7.0.19 and 6.4.0–6.4.16. According to vendor reports, crafted HTTP requests may be used to bypass a previously applied symbolic-link persistency patch; an attacker would first need the product to be compromised at the filesystem level via some other vulnerability before exploiting this issue. The weakness is classified as CWE-200 (Exposure of Sensitive Information).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Which versions of Fortinet FortiOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.6.0 – 7.6.1 | |
| 7.x | 7.4.0 – 7.4.6 | |
| 7.x | 7.2.0 – 7.2.13 | |
| 7.x | 7.0.0 – 7.0.19 | |
| 6.x | 6.4.0 – 6.4.16 |
Is CVE-2025-68686 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-27, and U.S. federal agencies were required to apply mitigations or fixes by 2026-08-10.
How to fix CVE-2025-68686
- Follow Fortinet’s official guidance and mitigations as published for CVE-2025-68686.
- Restrict network exposure of FortiOS management interfaces to trusted networks and VPNs; block HTTP access from the internet.
- Hunt for signs of filesystem compromise on affected FortiOS devices and remediate any unauthorized changes before applying mitigations.
- Enable and review detailed logging and alerts for anomalous HTTP requests and post-exploit persistence indicators.
Frequently asked questions
Is CVE-2025-68686 being actively exploited?
CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog on 2026-07-27, with a required remediation date of 2026-08-10 for U.S. federal agencies.
Which FortiOS versions are affected by CVE-2025-68686?
FortiOS versions affected are 7.6.0–7.6.1, 7.4.0–7.4.6, 7.2.0–7.2.13, 7.0.0–7.0.19 and 6.4.0–6.4.16.
Is there a patch for CVE-2025-68686?
No fixed versions are listed in the available data; follow Fortinet’s published mitigations and guidance for this vulnerability.
Does CVE-2025-68686 require authentication?
Exploit paths reference crafted HTTP requests that can be sent by unauthenticated actors, but the vulnerability description states an attacker would first need the device compromised at the filesystem level via another vulnerability.
References
- nvd.nist.gov/vuln/detail/CVE-2025-68686
- cve.org/CVERecord?id=CVE-2025-68686
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686
- fortiguard.fortinet.com/psirt/FG-IR-25-934
- All Fortinet CVEs on CVE Radar
- CVEs published in September 2026