Medium severity5.9CISA KEVNVD Advisory· Published Feb 10, 2026· Updated Jul 28, 2026
CVE-2025-68686
CVE-2025-68686
Description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.4.0,<7.4.7
- cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:*range: 7.6.0
- (no CPE)range: 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions
Patches
Vulnerability mechanics
References
2- fortiguard.fortinet.com/psirt/FG-IR-25-934nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
5- Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DaySecurityWeek · Jul 28, 2026
- CISA Warns of Fortinet FortiOS Vulnerability Exploited in AttacksCyber Security News · Jul 28, 2026
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection FlawThe Hacker News · Jul 28, 2026
- Fortinet CVE-2025-68686 Added to CISA KEV Under Active ExploitationVypr Intelligence · Jul 27, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts