Knox CVE Database
/
CVE-2025-68686
Medium
5.9

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Added to the CISA KEV catalog:
July 27, 2026

Overview

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Vulnerability details

Affected vendor
Fortinet
Affected product
FortiOS
Weakness type (CWE)
CWE-200

CVE-2025-68686 is a CWE-200 information exposure flaw in Fortinet FortiOS affecting versions across the 6.4 through 7.6 branches. The weakness class describes a condition where sensitive information becomes accessible to an actor who should not have it. In this case, Fortinet previously patched a symbolic link persistency mechanism that attackers had used in post-exploit scenarios to maintain filesystem access. This vulnerability represents a bypass of that patch, meaning the remediation itself was incomplete and the underlying exposure path remained reachable via crafted HTTP requests.


This flaw is chained: an attacker must have already compromised the FortiOS device at the filesystem level through a separate vulnerability before CVE-2025-68686 becomes relevant. With that prior foothold established, the attacker sends crafted HTTP requests to the FortiOS management or SSL-VPN interface to bypass the symbolic link patch. Successful exploitation restores or maintains access to sensitive filesystem content on the device, effectively nullifying the remediation that defenders believed had closed the post-exploit persistence channel. CISA has added this to the Known Exploited Vulnerabilities catalog.

Severity and impact

5.9
Medium
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review FortiOS HTTP access logs for anomalous requests to management or SSL-VPN interfaces originating from sources with no corresponding authenticated session, particularly on devices that have previously been assessed for compromise.
  • Audit the FortiOS filesystem for unexpected symbolic links in directories that should not contain them, especially following any prior incident response activity that applied the original symbolic link patch.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 10, 2026

Additional hardening

  • Restrict management and SSL-VPN interface access to explicitly allowlisted IP ranges via firewall policy; remove any public-facing exposure of these interfaces.
  • Conduct forensic triage per CISA's published Forensics Triage Requirements before patching, as prior compromise may have pre-positioned the symbolic link mechanism.
  • Disable SSL-VPN entirely if the feature is not operationally required, reducing the attack surface available to a chained attacker.
  • Segment FortiOS management interfaces onto a dedicated out-of-band network unreachable from general user or internet traffic.

Key dates

Published (NVD)
February 10, 2026
Added to CISA KEV
July 27, 2026
Remediation deadline
August 10, 2026
Last updated
July 28, 2026

References

Frequently asked questions

Does CVE-2025-68686 affect my FedRAMP authorization?

If Fortinet FortiOS runs inside your authorization boundary, CVE-2025-68686 directly affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog, with a remediation deadline of August 10, 2026. An unpatched KEV within your boundary is an assessor finding — one you must either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it first.

How does Knox help me handle CVE-2025-68686?

Remediating Fortinet FortiOS is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation in, along with continuous compliance monitoring and audit-artifact coverage to help you document the fix for your next assessment. The work is yours to apply; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including exposures like CVE-2025-68686. That means gaps surface during ongoing monitoring rather than only when an assessor flags them at review time, giving your team earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2025-68686 isn't remediated by August 10, 2026?

Missing the August 10, 2026 deadline turns CVE-2025-68686 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult agency conversation. Meeting the deadline keeps your authorization clean and the relationship with your sponsoring agency intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting