CVE-2025-68686 · Moderate · CISA KEV

Fortinet FortiOS: Post-Exploitation Information Exposure in KEV

Threat Engine Auto-Feed · data current as of 2026-07-27

CVE-2025-68686 in Fortinet FortiOS is an information exposure vulnerability that allows a remote unauthenticated attacker to bypass a patch for a symbolic link persistency mechanism. This vulnerability is listed in CISA KEV, indicating it has been exploited in the wild, but requires prior filesystem compromise.

  • CVSS:
  • EPSS percentile: 0.38495
  • Exploitation pressure: 48/100 (Moderate)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 38th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability involves an exposure of sensitive information to an unauthorized actor. Specifically, it allows an attacker to bypass a security fix related to how symbolic links are handled, which could lead to persistent access or information disclosure after an initial compromise.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using Fortinet FortiOS, especially those with internet-facing instances or a history of prior compromises.
  • Financial services and Technology sectors, due to assessed targeting by relevant threat actors.

Misconfigurations that escalate it

  • Lack of robust network segmentation that could limit an attacker's lateral movement post-initial compromise.
  • Insufficient monitoring for filesystem-level changes or unusual HTTP requests on FortiOS devices.

High-impact scenarios

  • An attacker, having already gained initial access to the filesystem, could leverage this vulnerability to maintain persistence or exfiltrate sensitive information, bypassing existing security controls.
  • Compromised FortiOS devices could serve as a pivot point for further network intrusion, data theft, or ransomware deployment, particularly in targeted sectors.

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor FortiOS device logs for unusual HTTP requests or filesystem modifications, especially after any suspected compromise.
  • Implement network intrusion detection systems (NIDS) to flag anomalous traffic patterns originating from or directed at FortiOS devices.

Contain

  • Isolate any FortiOS devices suspected of compromise to prevent further lateral movement.
  • Review and revoke any potentially compromised credentials or access tokens associated with the affected device.

Patch

  • Apply vendor-provided patches for CVE-2025-68686 and any other related vulnerabilities in Fortinet FortiOS as soon as they become available.

Frontier verdict — Moderate

Prioritize patching for Fortinet FortiOS due to its inclusion in CISA KEV, indicating active exploitation, despite requiring prior filesystem compromise.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.