CVE-2025-68686: 
FortiOS vulnerability analysis and mitigation

Overview

CVE-2025-68686 is an information disclosure vulnerability (CWE-200) in Fortinet FortiOS SSL-VPN that allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in post-exploit scenarios, via crafted HTTP requests. Affected versions include FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, and all versions of FortiOS 7.2, 7.0, and 6.4. Exploitation requires that the attacker has already compromised the device via another vulnerability at the filesystem level. It carries a CVSS v3.1 base score of 5.3–5.9 (Medium) (FortiGuard Advisory). The vulnerability was publicly disclosed on February 10, 2026, and was reported by Peter Gabaldon from ITRESIT under responsible disclosure (FortiGuard Advisory).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), specifically within the FortiOS SSL-VPN component. The vulnerability allows an attacker who has already achieved filesystem-level access — through a separate, prior exploit — to bypass Fortinet's previously deployed patch for the symbolic link persistency mechanism, a technique observed in post-exploitation activity on FortiGate devices. Exploitation is carried out via crafted HTTP requests that circumvent the existing patch controls, enabling read-only access to sensitive filesystem content. Devices that have never had SSL-VPN enabled are not impacted by this issue (FortiGuard Advisory). A technical write-up on the patch bypass mechanism was published by the reporting researcher (ITRESIT Labs).

Impact

Successful exploitation results in high confidentiality impact, allowing an attacker with prior filesystem-level access to read sensitive information from the FortiOS system via the SSL-VPN interface without authentication. Integrity and availability are not directly affected by this vulnerability. The primary risk is that threat actors who have already established a foothold on a FortiGate device can leverage this bypass to maintain persistent read access to sensitive data — such as credentials or configuration files — even after the original symbolic link patch was applied (FortiGuard Advisory).

Exploitability

As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation specifically for CVE-2025-68686 (FortiGuard Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.03%, reflecting a low probability of near-term exploitation. However, the vulnerability is a bypass of a patch for a previously exploited technique (symbolic link persistence), meaning threat actors already familiar with FortiGate post-exploitation tradecraft may be positioned to leverage it. A virtual patch (FG-VD-60389.0day) is available in FMWP database update 26.033 for organizations using FortiManager (FortiGuard Advisory).

Exploitation steps

  1. Prerequisite — Initial Compromise: The attacker must first compromise the FortiGate device via a separate vulnerability (e.g., a known SSL-VPN authentication bypass or RCE) to gain filesystem-level access.
  2. Establish Symbolic Link Persistence: Using the existing filesystem access, the attacker plants or leverages a symbolic link within the SSL-VPN web root pointing to sensitive areas of the filesystem — a technique previously observed in FortiGate post-exploitation activity.
  3. Bypass the Existing Patch: Craft specific HTTP requests targeting the SSL-VPN interface that exploit the incomplete patch for the symbolic link persistency mechanism, bypassing the controls Fortinet introduced to block this technique.
  4. Exfiltrate Sensitive Data: The crafted requests allow unauthenticated read access to files exposed via the symbolic link, potentially including configuration files, credentials, or other sensitive data stored on the device (FortiGuard Advisory, ITRESIT Labs).

Indicators of compromise

  • Network: Unusual or crafted HTTP GET/POST requests to SSL-VPN endpoints that reference unexpected file paths or symbolic link targets; unauthenticated requests to SSL-VPN web interface accessing files outside expected directories.
  • File System: Presence of unexpected symbolic links within the SSL-VPN web root or related directories pointing to sensitive filesystem locations (e.g., /etc/, /data/, configuration directories); files or directories with anomalous ownership or timestamps.
  • Logs: FortiOS SSL-VPN access logs showing requests to unusual or non-standard paths; repeated access attempts from external IPs to SSL-VPN endpoints with path traversal patterns.
  • Process/Configuration: Evidence of prior compromise via another vulnerability (e.g., unexpected admin accounts, modified configurations, or signs of earlier exploitation of known FortiOS CVEs) (FortiGuard Advisory).

Mitigation and workarounds

Fortinet has released patched versions addressing CVE-2025-68686: upgrade FortiOS 7.6.x to 7.6.2 or later, and FortiOS 7.4.x to 7.4.7 or later. All FortiOS 7.2, 7.0, and 6.4 versions are affected with no in-branch fix; users must migrate to a supported, patched release. Organizations can use Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan their migration. As an interim measure, a virtual patch (FG-VD-60389.0day) is available in FMWP database update 26.033 for FortiManager-managed environments. Additionally, disabling SSL-VPN entirely on devices where it is not required eliminates exposure, as devices that never had SSL-VPN enabled are not impacted (FortiGuard Advisory).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Fortinet products, including CVE-2025-68686, recommending prompt patching (CIS Advisory). Belgium's Centre for Cybersecurity (CCB) also issued a warning urging organizations to patch Fortinet products immediately. The reporting researcher, Peter Gabaldon of ITRESIT, published a technical blog post detailing the symlink persistence patch bypass mechanism (ITRESIT Labs). Community interest was moderate, with the vulnerability appearing in threat aggregators and security feeds shortly after disclosure.

Additional resources


Source: This report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesSep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management