Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
Fortinet FortiOS has a vulnerability (CVE-2025-68686) that exposes sensitive information to unauthorized actors. A remote attacker can bypass a previously implemented patch for symbolic link persistency by sending crafted HTTP requests, but only after first compromising the system via another filesystem-level exploit. CISA confirmed this flaw is actively being exploited in the wild and added it to its Known Exploited Vulnerabilities catalog on July 27, 2026. The vulnerability affects organizations using Fortinet FortiOS, potentially exposing sensitive data if attackers chain it with other exploits. This poses a significant risk as FortiOS is widely used for network security, making it a high-value target. CISA urges administrators to apply patches immediately to mitigate the threat, given the active exploitation.
Key Takeaways
- CVE-2025-68686 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- Fortinet FortiOS: Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability.