VULNERABILITY OVERVIEW
An Exposure of Sensitive Information (CWE-200) vulnerability in FortiOS SSL-VPN allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistence mechanism observed in previous nation-state post-exploitation campaigns, via crafted HTTP requests. Exploitation requires the device to have already been compromised at the filesystem level through another vulnerability, making this a post-exploitation persistence extender. CISA added to KEV on July 27, 2026 with a remediation deadline of August 10, 2026; exploitation is confirmed in the wild in conjunction with prior filesystem-level compromises.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
HIGH
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:N · A:N
AFFECTED VERSIONS
FortiOS 7.6.0–7.6.1, FortiOS 7.4.0–7.4.6, FortiOS 7.2 (all versions), FortiOS 7.0 (all versions), FortiOS 6.4 (all versions); fixed in 7.6.2+ and 7.4.7+CITATIONS
- → https://fortiguard.fortinet.com/psirt/FG-IR-25-934
- → https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- → https://windowsforum.com/security-alerts.84/cisa-kev-adds-velocloud-orchestrator-rce-and-fortios-ssl-vpn-flaw.440641/
- → https://www.redlegg.com/blog/security-bulletin-ssl-vpn-symlink-persistence-patch-bypass-in-fortios