DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2025-68686PUBLISHED: 2026-02-10
MEDIUMCVE-2025-68686★ CISA KEV LISTED

Fortinet FortiOS SSL-VPN Symlink Persistence Patch Bypass

VENDOR: Fortinet//PRODUCT: FortiOS SSL-VPN
5.3
MEDIUM
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

An Exposure of Sensitive Information (CWE-200) vulnerability in FortiOS SSL-VPN allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistence mechanism observed in previous nation-state post-exploitation campaigns, via crafted HTTP requests. Exploitation requires the device to have already been compromised at the filesystem level through another vulnerability, making this a post-exploitation persistence extender. CISA added to KEV on July 27, 2026 with a remediation deadline of August 10, 2026; exploitation is confirmed in the wild in conjunction with prior filesystem-level compromises.

Attack Vector
NETWORK
Attack Complexity
HIGH
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:N · A:N
AFFECTED VERSIONSFortiOS 7.6.0–7.6.1, FortiOS 7.4.0–7.4.6, FortiOS 7.2 (all versions), FortiOS 7.0 (all versions), FortiOS 6.4 (all versions); fixed in 7.6.2+ and 7.4.7+
  • https://fortiguard.fortinet.com/psirt/FG-IR-25-934
  • https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
  • https://windowsforum.com/security-alerts.84/cisa-kev-adds-velocloud-orchestrator-rce-and-fortios-ssl-vpn-flaw.440641/
  • https://www.redlegg.com/blog/security-bulletin-ssl-vpn-symlink-persistence-patch-bypass-in-fortios
SHARE BRIEF:✕ Post on Xin Share on LinkedIn