Back to overview

CVE-2025-68686

MEDIUM KEV CISA Exploitation: ACTIVE
5.3
CVSS 3.1
Description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Metadata

CVE ID
CVE-2025-68686
State
PUBLISHED
Assigner
fortinet
Reserved
2025-12-23 15:55 UTC
Published
2026-02-10 15:39 UTC
Last updated
2026-07-28 03:55 UTC
Primary CWE
CWE-200
Information disclosure
Vendor / Product
Fortinet / FortiOS
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
no
Tech. Impact
partial
CISA Known Exploited Vulnerability
Vulnerability name
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Vendor
Fortinet
Product
FortiOS
Added to KEV
2026-07-27
Due date
2026-08-10
Ransomware
Not known
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA description
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Affected products (1)
VendorProductPlatformVersions
Fortinet FortiOS 7.6.0 ≤ 7.6.1, 7.4.0 ≤ 7.4.6, 7.2.0 ≤ 7.2.13, 7.0.0 ≤ 7.0.19 …
Weakness (CWE)
CWESourceDescription
CWE-200 cna Information disclosure
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
References (1)
Back to overview