The Cybersecurity and Infrastructure Security Agency (CISA) has identified a significant vulnerability in Fortinet’s FortiOS, designated as CVE-2025-68686. This vulnerability is actively being exploited, prompting CISA to add it to their Known Exploited Vulnerabilities (KEV) catalog.
Understanding the Fortinet FortiOS Vulnerability
Fortinet FortiOS, the backbone of FortiGate firewalls and numerous security products by Fortinet, is currently exposed to a critical security flaw. This issue, which involves the unauthorized exposure of sensitive information, has been categorized under CWE-200. The vulnerability allows an attacker to bypass a patch intended to prevent a persistence method via symbolic links by sending crafted HTTP requests to susceptible devices.
For an attack to succeed, the threat actor must have previously compromised the FortiOS device through another vulnerability, gaining filesystem-level access. This prerequisite highlights the advanced nature of the attack.
Implications of Exploiting CVE-2025-68686
The exploitation of CVE-2025-68686 could potentially circumvent protections implemented to counter persistence tactics used in earlier attacks. Symbolic links, or symlinks, are utilized to reference other files or directories within the system’s filesystem. Once inside a vulnerable system, attackers may exploit these symlinks to maintain persistence, access restricted files, or hinder remediation efforts.
Organizations relying on the belief that their previously compromised devices are secure may face significant risks if a patch bypass occurs via symbolic links. CISA has not yet confirmed any connection between this vulnerability and ransomware attacks, but its active exploitation status warrants urgent attention.
Recommended Actions for Organizations
Federal agencies are required to adhere to CISA’s directives, implementing necessary mitigations by August 10, 2026. Affected organizations should refer to Fortinet’s guidance and follow the Binding Operational Directive 26-04, which prioritizes security updates based on risk levels.
Security teams are advised to identify all FortiOS deployments, assess internet-facing management interfaces or VPN services, and consult Fortinet advisories for updates or possible mitigations. Investigations should focus on detecting signs of prior breaches, as filesystem-level access is necessary for exploiting this vulnerability. CISA also recommends following their Forensics Triage Requirements during such investigations.
If no mitigation is available, organizations might need to consider isolating affected systems from the network or discontinuing their use until a secure fix is implemented. This addition to the KEV list underscores the vulnerability of perimeter appliances to persistent threats targeting corporate networks.
