FortiOS info leak exploited in the wild (CVE-2025-68686)
CVE-2025-68686
CVE-2025-68686: FortiOS info leak exploited in the wild bypasses symlink patch. Attackers with filesystem-level access can read sensitive data. CISA KEV confirmed; update to 7.6.2 or later.
Actively exploited in the wild - CVE-2025-68686 is a medium exposure of sensitive information vulnerability in Fortinet FortiOS versions 6.4 through 7.6.1 that lets remote unauthenticated attackers bypass a patch for a symbolic link persistency mechanism after compromising the filesystem.
Overview
CVE-2025-68686 is an information disclosure vulnerability (CWE-200) affecting Fortinet FortiOS across multiple version branches. The flaw allows a remote, unauthenticated attacker to bypass a previously released patch designed to address a symbolic link persistency mechanism observed in post-exploitation scenarios. An attacker must first compromise the product at the filesystem level through another vulnerability before exploiting this issue.
The vulnerability impacts the following FortiOS versions:
- 6.4 (all versions)
- 7.0 (all versions)
- 7.2 (all versions)
- 7.4.0 through 7.4.6
- 7.6.0 through 7.6.1
The issue carries a CVSS score of 5.9 (Medium) with a network attack vector, high attack complexity, and no privileges required.
Impact on Affected Systems
An attacker who has already achieved filesystem-level compromise of a FortiOS device can use crafted HTTP requests to exploit the incomplete symlink patch. This enables the attacker to read sensitive information from the target system, potentially including configuration files, credentials, or other data that should be protected. The CISA Known Exploited Vulnerabilities (KEV) catalog confirms active exploitation of this vulnerability in the wild.
Fortinet has rated this vulnerability as Medium severity because exploitation requires prior compromise at the filesystem level, meaning the attacker must already have a foothold within the device. However, the active exploitation status makes this a significant concern for organizations running affected FortiOS versions.
Actionable Remediation and Mitigation
- Update FortiOS: Upgrade to FortiOS 7.6.2 or later if running 7.6.0-7.6.1. For 7.4 branch, update to 7.4.7 or later. For 6.4, 7.0, and 7.2 branches, check the Fortinet advisory for specific patched versions as these branches may require upgrades to supported versions.
- Review security posture: Since this vulnerability requires prior filesystem compromise, review logs for signs of initial access vectors like other FortiOS CVEs (e.g., CVE-2023-27997, CVE-2024-21762).
- Implement network segmentation: Restrict management interfaces to trusted IP ranges to reduce exposure surface.
Security Insight
This vulnerability illustrates a recurring pattern where patch bypasses emerge after initial fixes for post-exploitation mechanisms. The fact that CISA KEV lists this as actively exploited suggests threat actors are methodically chaining FortiOS bugs to maintain persistent access. Organizations should apply this patch with urgency to break the attack chain, especially since the related Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer indicates broader targeting of Fortinet products. For broader context on recent threats, see our Weekly Threat Roundup: Nx Console Supply Chain Attack (May 25-31).
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file ...
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network....
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo ...
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network....