Medium 5.9 Actively Exploited

FortiOS info leak exploited in the wild (CVE-2025-68686)

CVE-2025-68686

By Yazoul AI · automated

CVE-2025-68686: FortiOS info leak exploited in the wild bypasses symlink patch. Attackers with filesystem-level access can read sensitive data. CISA KEV confirmed; update to 7.6.2 or later.

Affected: Fortinet Fortios

Actively exploited in the wild - CVE-2025-68686 is a medium exposure of sensitive information vulnerability in Fortinet FortiOS versions 6.4 through 7.6.1 that lets remote unauthenticated attackers bypass a patch for a symbolic link persistency mechanism after compromising the filesystem.

Overview

CVE-2025-68686 is an information disclosure vulnerability (CWE-200) affecting Fortinet FortiOS across multiple version branches. The flaw allows a remote, unauthenticated attacker to bypass a previously released patch designed to address a symbolic link persistency mechanism observed in post-exploitation scenarios. An attacker must first compromise the product at the filesystem level through another vulnerability before exploiting this issue.

The vulnerability impacts the following FortiOS versions:

  • 6.4 (all versions)
  • 7.0 (all versions)
  • 7.2 (all versions)
  • 7.4.0 through 7.4.6
  • 7.6.0 through 7.6.1

The issue carries a CVSS score of 5.9 (Medium) with a network attack vector, high attack complexity, and no privileges required.

Impact on Affected Systems

An attacker who has already achieved filesystem-level compromise of a FortiOS device can use crafted HTTP requests to exploit the incomplete symlink patch. This enables the attacker to read sensitive information from the target system, potentially including configuration files, credentials, or other data that should be protected. The CISA Known Exploited Vulnerabilities (KEV) catalog confirms active exploitation of this vulnerability in the wild.

Fortinet has rated this vulnerability as Medium severity because exploitation requires prior compromise at the filesystem level, meaning the attacker must already have a foothold within the device. However, the active exploitation status makes this a significant concern for organizations running affected FortiOS versions.

Actionable Remediation and Mitigation

  • Update FortiOS: Upgrade to FortiOS 7.6.2 or later if running 7.6.0-7.6.1. For 7.4 branch, update to 7.4.7 or later. For 6.4, 7.0, and 7.2 branches, check the Fortinet advisory for specific patched versions as these branches may require upgrades to supported versions.
  • Review security posture: Since this vulnerability requires prior filesystem compromise, review logs for signs of initial access vectors like other FortiOS CVEs (e.g., CVE-2023-27997, CVE-2024-21762).
  • Implement network segmentation: Restrict management interfaces to trusted IP ranges to reduce exposure surface.

Security Insight

This vulnerability illustrates a recurring pattern where patch bypasses emerge after initial fixes for post-exploitation mechanisms. The fact that CISA KEV lists this as actively exploited suggests threat actors are methodically chaining FortiOS bugs to maintain persistent access. Organizations should apply this patch with urgency to break the attack chain, especially since the related Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer indicates broader targeting of Fortinet products. For broader context on recent threats, see our Weekly Threat Roundup: Nx Console Supply Chain Attack (May 25-31).

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.