DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // CISA-KEV-2026-07-27 // PUBLISHED 2026-07-27

CISA KEV: Fortinet FortiOS SSL-VPN Sensitive Information Exposure — Patch Bypass Actively Exploited (CVE-2025-68686)

CVE-2025-68686 is an information exposure vulnerability (CWE-200) in Fortinet FortiOS SSL-VPN that allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism used in post-exploitation persistence cases. The attacker must first gain filesystem-level access via a separate vulnerability before abusing this flaw to re-access sensitive resources that should have been sealed by the prior patch. CISA added it to the KEV on July 27, 2026 with a remediation deadline of August 10, 2026.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Fortinet FortiOS SSL-VPN (multiple versions — consult FortiGuard PSIRT advisory for full version matrix)
MEDIUM
LIMITED
PATCHED

Apply the updated FortiOS patches released by Fortinet in February 2026 that address CVE-2025-68686. Restrict SSL-VPN management interfaces to trusted IP ranges. Conduct forensic triage per CISA BOD 26-04 implementation guidance to determine if symbolic link artifacts are present on the filesystem. Review for residual IOCs from prior FortiOS compromises.

Hunt for unexpected symbolic links in FortiOS filesystem paths associated with post-exploitation persistence. Review FortiOS logs for crafted HTTP requests targeting SSL-VPN endpoints from untrusted sources. Correlate with prior FortiOS exploitation IOCs (e.g., modified files in /data2 or /data paths). Use FortiGuard recommended IoC scan scripts if previously compromised.

  • https://www.fortiguard.com/psirt
  • https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2025-68686
SHARE BRIEF:✕ Post on Xin Share on LinkedIn