cbcvebase.
CVE-2025-68686
published 2026-02-10

CVE-2025-68686: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0…

PriorityP184medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-08-10
Exploited in the wild
EPSS
0.48%
38.5th percentile
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios>= 6.4.0 < 7.4.77.4.7
fortinetfortios6.4.0 – 6.4.16
fortinetfortios7.0.0 – 7.0.19
fortinetfortios7.2.0 – 7.2.13
fortinetfortios7.4.0 – 7.4.6
fortinetfortios>= 7.6.0 < 7.6.27.6.2
fortinetfortios7.6.0 – 7.6.1

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck5.9MEDIUM
cisa5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.