CISA Flags Actively Exploited FortiOS Flaw That Bypasses Patch Mitigations
CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog on July 27, 2026, flagging it as a critical actively exploited flaw in Fortinet's FortiOS. The vulnerability allows attackers who have already gained file-system-level access to a FortiOS device to plant malicious symlinks that persist even after firmware updates or patches are applied. By sending crafted HTTP requests to the SSL-VPN web interface, an attacker can read sensitive files such as credentials, configurations, and encryption keys. Affected versions span FortiOS 6.4 through 7.6.1, with Fortinet recommending upgrades to versions 7.4.7, 7.6.2, or later alongside full device rebuilds and credential rotation. Security teams are advised to restrict or disable SSL-VPN interface exposure and audit devices for symlink artifacts, as standard patching alone does not eliminate existing compromises.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in