## Overview
CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) list on July 27, 2026. This vulnerability affects multiple versions of Fortinet's FortiOS, specifically versions 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, and all versions of 7.2, 7.0, and 6.4. The addition to the KEV list indicates a federal deadline for remediation, highlighting the urgency of the issue.
## Technical Details
CVE-2025-68686 is classified as an Exposure of Sensitive Information to an Unauthorized Actor vulnerability (CWE-200). It allows a remote unauthenticated attacker to exploit a flaw in the symbolic link persistency mechanism. Attackers can use crafted HTTP requests to bypass previously implemented patches. However, exploitation requires that the attacker first compromise the FortiOS product through another vulnerability at the filesystem level.
## Impact
The vulnerability poses a significant risk. If exploited, it could lead to unauthorized access to sensitive information. This could allow attackers to gather intelligence or further compromise the affected systems. The CVSS score of 5.9 indicates a moderate severity, but the potential for exploitation makes it critical to address.
## Mitigation
Fortinet has released patches for affected versions of FortiOS. Organizations should immediately apply these updates to mitigate the risk associated with CVE-2025-68686. Regularly review security configurations and monitor for any signs of compromise. Implementing additional security measures, such as network segmentation and intrusion detection systems, can further protect against exploitation.
CSURFACE Threat Sensor