CVE-2025-68686
published 2026-02-10CVE-2025-68686: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0…
PriorityP184medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-08-10
Exploited in the wild
EPSS
0.48%
38.5th percentile
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 7.4.7 | 7.4.7 |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.19 | — |
| fortinet | fortios | 7.2.0 – 7.2.13 | — |
| fortinet | fortios | 7.4.0 – 7.4.6 | — |
| fortinet | fortios | >= 7.6.0 < 7.6.2 | 7.6.2 |
| fortinet | fortios | 7.6.0 – 7.6.1 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck5.9MEDIUM
cisa5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
cisa·2026-07-27·CVSS 5.9
CVE-2025-68686 [MEDIUM] CWE-200 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Vulnerability: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Affected: Fortinet FortiOS
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab
Fortinet
SSL-VPN Symlink Persistence Patch Bypass
vendor_fortinet·2026-02-10·CVSS 5.9
CVE-2025-68686 [MEDIUM] CWE-200 SSL-VPN Symlink Persistence Patch Bypass
FG-IR-25-934: SSL-VPN Symlink Persistence Patch Bypass
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CVEs: CVE-2025-68686
CWEs: CWE-200
CVSS: 5.9 (medium)
Affected products: FortiOS, Fortinet
VulDB
Fortinet FortiOS up to 7.6.1 HTTP information disclosure (FG-IR-25-934)
vuldb·2026-07-28·CVSS 5.9
CVE-2025-68686 [MEDIUM] Fortinet FortiOS up to 7.6.1 HTTP information disclosure (FG-IR-25-934)
A vulnerability was found in Fortinet FortiOS up to 6.4.16/7.0.19/7.2.13/7.4.6/7.6.1. It has been classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Handler. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2025-68686. The attack may be initiated remotely. In addition, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-839g-m33x-3w78: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7
ghsa_unreviewed·2026-02-10
CVE-2025-68686 [MEDIUM] CWE-200 GHSA-839g-m33x-3w78: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
VulnCheck
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
vulncheck·2025·CVSS 5.9
CVE-2025-68686 [MEDIUM] CWE-200 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Affected: Fortinet FortiOS
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 g
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-59718 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2025-59718 [MEDIUM] CVE-2025-59718 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59718 :
FortiOS vulnerability analysis and mitigation
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Source : NVD
## 9.8
Score
Published December 9, 2025
Severity CRITICAL
CNA Score 9.8
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV
Wiz
CVE-2024-47570 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.6
CVE-2024-47570 [MEDIUM] CVE-2024-47570 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-47570 :
FortiOS vulnerability analysis and mitigation
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only administrator to retrieve API tokens of other administrators via observing REST API logs, if REST API logging is enabled (non-default configuration).
Source : NVD
## 6.6
Score
Published December 9, 2025
Severity MEDIUM
CNA Score 6.6
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Du
Wiz
CVE-2025-62631 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2025-62631 [MEDIUM] CVE-2025-62631 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62631 :
FortiOS vulnerability analysis and mitigation
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the attacker's control
Source : NVD
## 5.6
Score
Published December 9, 2025
Severity MEDIUM
CNA Score 5.6
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
c
Wiz
CVE-2025-62439 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2025-62439 [MEDIUM] CVE-2025-62439 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62439 :
FortiOS vulnerability analysis and mitigation
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.
Source : NVD
## 4.2
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 4.2
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and li
Wiz
CVE-2026-22153 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2026-22153 [MEDIUM] CVE-2026-22153 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22153 :
FortiOS vulnerability analysis and mitigation
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.
Source : NVD
## 8.1
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:o:fortinet:fortios
Sources
Linux Severity HIGH Has Fix Added at: Feb 11, 202
Wiz
CVE-2025-68686 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2025-68686 [MEDIUM] CVE-2025-68686 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68686 :
FortiOS vulnerability analysis and mitigation
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Source : NVD
## 5.9
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
Wiz
CVE-2025-64157 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2025-64157 [MEDIUM] CVE-2025-64157 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64157 :
FortiOS vulnerability analysis and mitigation
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via specifically crafted configuration.
Source : NVD
## 7.2
Score
Published February 10, 2026
Severity HIGH
CNA Score 6.7
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:o:fortinet:fortios
Sources
Linux Severity HIGH Has Fix Added at: Fe
Wiz
CVE-2026-24858 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2026-24858 [MEDIUM] CVE-2026-24858 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24858 :
FortiOS vulnerability analysis and mitigation
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 ma
Wiz
CVE-2025-25249 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-25249 [HIGH] CVE-2025-25249 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-25249 :
FortiOS vulnerability analysis and mitigation
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Source : NVD
## 9.8
Score
Published January 13, 2026
Severity CRITICAL
CNA Score 8.1
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:
Wiz
CVE-2025-55018 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2025-55018 [MEDIUM] CVE-2025-55018 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55018 :
FortiOS vulnerability analysis and mitigation
An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header
Source : NVD
## 5.8
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.9
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:
Wiz
CVE-2024-40593 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2024-40593 [MEDIUM] CVE-2024-40593 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-40593 :
FortiOS vulnerability analysis and mitigation
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
Source : NVD
## 4.4
Score
Published December 11, 2025
Severity MEDIUM
CNA Score 6.0
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA
2026-02-10
Published
2026-07-27
Added to CISA KEV
Exploited in the wild