Fortinet FortiOS flaw can expose sensitive information
Fortinet FortiOS can expose sensitive information after an attacker has already compromised it through another vulnerability. CISA lists CVE-2025-68686 among vulnerabilities exploited in real attacks.
- Severity
- MediumCVSS 3.1 · 5.9
- Fix
- Fixed in 7.6.2Fix recorded on Aug 26, 2026
- Affected versions
- 7.6.0 through 7.6.1; 7.4.0 through 7.4.6; 7.2.0 through 7.2.13+2 more
- Weakness
- CWE-200Exposure of Sensitive Information
- Exploit likelihood
- 30% in 30 daysEPSS, higher than 98% of known flaws
- Affects
- FortiOS
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Jul 27, 2026
- Federal fix deadline
- Aug 10, 2026
How it works
- An attacker must first compromise FortiOS at the filesystem level through another vulnerability.
- They can then send specially crafted HTTP requests.
- FortiOS may let those requests bypass a patch designed to stop a filesystem shortcut from surviving after compromise.
- This can expose sensitive information to a remote unauthenticated attacker.
What to do
Compare the installed FortiOS version with the affected ranges in Fortinet's advisory. A matching version shows exposure to the flaw, not proof that the system was compromised.
Upgrade to FortiOS 7.6.2 or above, or FortiOS 7.4.7 or above. For FortiOS 7.2, 7.0, and 6.4, follow the vendor instructions referenced by CISA and Fortinet's advisory.
Technical details
CVE-2025-68686 is a CWE-200 information-disclosure flaw in FortiOS. After another filesystem-level compromise, crafted HTTP requests can bypass a patch intended to stop a filesystem shortcut from surviving post-compromise.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity High Attack depends on conditions outside the attacker's control
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact None No data tampering
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Open in FIRST.org calculatorReferences
- cisa.gov · known-exploited-vulnerabilities-catalog us government resource Observed exploitation US Government Resource
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2025-68686 third party advisory vdb entry
- cvefeed.io · CVE-2025-68686 third party advisory vdb entry
- cveawg.mitre.org · CVE-2025-68686
- fortiguard.fortinet.com · FG-IR-25-934