ADVISORY SUMMARY
CVE-2025-68686 is an information exposure vulnerability (CWE-200) in Fortinet FortiOS SSL-VPN that allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism used in post-exploitation persistence cases. The attacker must first gain filesystem-level access via a separate vulnerability before abusing this flaw to re-access sensitive resources that should have been sealed by the prior patch. CISA added it to the KEV on July 27, 2026 with a remediation deadline of August 10, 2026.
AFFECTED SYSTEMS
MITIGATION GUIDANCE
Apply the updated FortiOS patches released by Fortinet in February 2026 that address CVE-2025-68686. Restrict SSL-VPN management interfaces to trusted IP ranges. Conduct forensic triage per CISA BOD 26-04 implementation guidance to determine if symbolic link artifacts are present on the filesystem. Review for residual IOCs from prior FortiOS compromises.
DETECTION SIGNATURES
Hunt for unexpected symbolic links in FortiOS filesystem paths associated with post-exploitation persistence. Review FortiOS logs for crafted HTTP requests targeting SSL-VPN endpoints from untrusted sources. Correlate with prior FortiOS exploitation IOCs (e.g., modified files in /data2 or /data paths). Use FortiGuard recommended IoC scan scripts if previously compromised.
REFERENCES
- → https://www.fortiguard.com/psirt
- → https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- → https://nvd.nist.gov/vuln/detail/CVE-2025-68686