CVE-2025-68686 · Moderate · CISA KEV
Fortinet FortiOS: Post-Exploitation Information Exposure in KEV
Threat Engine Auto-Feed · data current as of 2026-07-27
CVE-2025-68686 in Fortinet FortiOS is an information exposure vulnerability that allows a remote unauthenticated attacker to bypass a patch for a symbolic link persistency mechanism. This vulnerability is listed in CISA KEV, indicating it has been exploited in the wild, but requires prior filesystem compromise.
- CVSS:
- EPSS percentile: 0.38495
- Exploitation pressure: 48/100 (Moderate)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 38th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability involves an exposure of sensitive information to an unauthorized actor. Specifically, it allows an attacker to bypass a security fix related to how symbolic links are handled, which could lead to persistent access or information disclosure after an initial compromise.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using Fortinet FortiOS, especially those with internet-facing instances or a history of prior compromises.
- Financial services and Technology sectors, due to assessed targeting by relevant threat actors.
Misconfigurations that escalate it
- Lack of robust network segmentation that could limit an attacker's lateral movement post-initial compromise.
- Insufficient monitoring for filesystem-level changes or unusual HTTP requests on FortiOS devices.
High-impact scenarios
- An attacker, having already gained initial access to the filesystem, could leverage this vulnerability to maintain persistence or exfiltrate sensitive information, bypassing existing security controls.
- Compromised FortiOS devices could serve as a pivot point for further network intrusion, data theft, or ransomware deployment, particularly in targeted sectors.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor FortiOS device logs for unusual HTTP requests or filesystem modifications, especially after any suspected compromise.
- Implement network intrusion detection systems (NIDS) to flag anomalous traffic patterns originating from or directed at FortiOS devices.
Contain
- Isolate any FortiOS devices suspected of compromise to prevent further lateral movement.
- Review and revoke any potentially compromised credentials or access tokens associated with the affected device.
Patch
- Apply vendor-provided patches for CVE-2025-68686 and any other related vulnerabilities in Fortinet FortiOS as soon as they become available.
Frontier verdict — Moderate
Prioritize patching for Fortinet FortiOS due to its inclusion in CISA KEV, indicating active exploitation, despite requiring prior filesystem compromise.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.