CVE-2025-68686
MEDIUM · 5.9 KEV EPSS 1.3%KEV confirmation + active exploitation signals real threat; low EPSS and prerequisite compromise temper urgency slightly.
What: Fortinet FortiOS sensitive information disclosure (CWE-200) in versions 6.4–7.6.1 allowing remote unauthenticated bypass of post-exploit symbolic link persistence patch via crafted HTTP requests; requires prior compromise. CVSS 5.9 (medium).
Why it matters: KEV-listed as of 27 July 2026 (yesterday) with confirmed active exploitation. Fortinet immediately patching; defenders triaging affected FortiOS instances. Low EPSS (0.38%) reflects exploitation complexity—requires prior filesystem access—but KEV status signals threat actors weaponizing the bypass chain.
Where it's seen: CISA alert coverage across infosec social channels (Bluesky, Mastodon) in multiple languages; vendor advisories circulating. Chatter emphasizes "actively exploited" and urgent patching but no public PoC drops mentioned.
RISK: HIGH — KEV-listed with active exploitation; affects widely-deployed FortiOS appliances across multiple versions.
Description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N- Attack vector
- Network
- Complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- None
- Availability
- None
Affected versions
- fortinet/fortios
- 6.4.0 – < 7.4.7
- 7.6.0 – < 7.6.2