Knox CVE Database
/
CVE-2025-68686
Medium
5.9

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Added to the CISA KEV catalog:
July 27, 2026

Overview

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Vulnerability details

Affected vendor
Fortinet
Affected product
FortiOS
Weakness type (CWE)
CWE-200

CVE-2025-68686 is a CWE-200 information disclosure vulnerability in Fortinet FortiOS. The weakness class involves a product exposing sensitive data to an actor who should not have access to it. In this case, Fortinet previously patched a symbolic link persistency mechanism that attackers had used in post-exploit scenarios to maintain access or read sensitive files. This CVE represents a bypass of that patch: the fix was incomplete, leaving a path through which the underlying symbolic link technique could still be exercised via the HTTP interface.

This flaw is chained: an attacker must first compromise the FortiOS device at the filesystem level through a separate vulnerability before CVE-2025-68686 becomes relevant. Once that prior foothold exists, the attacker sends crafted HTTP requests to the FortiOS management or web interface to bypass the symbolic link persistency patch. Successful exploitation results in high confidentiality impact, allowing the attacker to read sensitive information from the device that the patch was intended to protect. The prior filesystem-level compromise is a hard precondition and limits direct exploitability.

Severity and impact

5.9
Medium
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review FortiOS HTTP access logs for anomalous or malformed requests to management and web interface endpoints, particularly from sources with no corresponding legitimate administrative session or authentication event.
  • Audit the FortiOS filesystem for unexpected symbolic links in directories accessible via the web interface, which would indicate the persistency mechanism has been re-established after patching.
  • Check for indicators of a prior compromise at the filesystem level, such as unexpected files, modified binaries, or unauthorized accounts, since this CVE is only reachable after an initial breach.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 10, 2026

Additional hardening

  • Restrict management interface access to dedicated, out-of-band administrative networks and block all direct internet exposure of the FortiOS web and management interfaces.
  • Apply CISA forensic triage requirements to any FortiOS device that may have been previously compromised, as the symbolic link technique is a post-exploit persistence mechanism requiring active investigation.
  • Disable or restrict HTTP-based management access where not operationally required, preferring CLI access over dedicated management channels with strict source IP controls.
  • Segment FortiOS management plane traffic from general user and internet-facing traffic to reduce the attack surface available to an attacker who has achieved initial filesystem access.

Key dates

Published (NVD)
February 10, 2026
Added to CISA KEV
July 27, 2026
Remediation deadline
August 10, 2026
Last updated
July 28, 2026

References

Frequently asked questions

Does CVE-2025-68686 affect my FedRAMP authorization?

If Fortinet FortiOS runs inside your authorization boundary, yes. CVE-2025-68686 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of August 10, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2025-68686?

Knox doesn't patch your software for you — remediating Fortinet FortiOS is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2025-68686 isn't remediated by August 10, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting