
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68686 is an information disclosure vulnerability (CWE-200) in Fortinet FortiOS SSL-VPN that allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in post-exploit scenarios, via crafted HTTP requests. Affected versions include FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, and all versions of FortiOS 7.2, 7.0, and 6.4. Exploitation requires that the attacker has already compromised the device via another vulnerability at the filesystem level. It carries a CVSS v3.1 base score of 5.3–5.9 (Medium) (FortiGuard Advisory). The vulnerability was publicly disclosed on February 10, 2026, and was reported by Peter Gabaldon from ITRESIT under responsible disclosure (FortiGuard Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), specifically within the FortiOS SSL-VPN component. The vulnerability allows an attacker who has already achieved filesystem-level access — through a separate, prior exploit — to bypass Fortinet's previously deployed patch for the symbolic link persistency mechanism, a technique observed in post-exploitation activity on FortiGate devices. Exploitation is carried out via crafted HTTP requests that circumvent the existing patch controls, enabling read-only access to sensitive filesystem content. Devices that have never had SSL-VPN enabled are not impacted by this issue (FortiGuard Advisory). A technical write-up on the patch bypass mechanism was published by the reporting researcher (ITRESIT Labs).
Successful exploitation results in high confidentiality impact, allowing an attacker with prior filesystem-level access to read sensitive information from the FortiOS system via the SSL-VPN interface without authentication. Integrity and availability are not directly affected by this vulnerability. The primary risk is that threat actors who have already established a foothold on a FortiGate device can leverage this bypass to maintain persistent read access to sensitive data — such as credentials or configuration files — even after the original symbolic link patch was applied (FortiGuard Advisory).
As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation specifically for CVE-2025-68686 (FortiGuard Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.03%, reflecting a low probability of near-term exploitation. However, the vulnerability is a bypass of a patch for a previously exploited technique (symbolic link persistence), meaning threat actors already familiar with FortiGate post-exploitation tradecraft may be positioned to leverage it. A virtual patch (FG-VD-60389.0day) is available in FMWP database update 26.033 for organizations using FortiManager (FortiGuard Advisory).
/etc/, /data/, configuration directories); files or directories with anomalous ownership or timestamps.Fortinet has released patched versions addressing CVE-2025-68686: upgrade FortiOS 7.6.x to 7.6.2 or later, and FortiOS 7.4.x to 7.4.7 or later. All FortiOS 7.2, 7.0, and 6.4 versions are affected with no in-branch fix; users must migrate to a supported, patched release. Organizations can use Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan their migration. As an interim measure, a virtual patch (FG-VD-60389.0day) is available in FMWP database update 26.033 for FortiManager-managed environments. Additionally, disabling SSL-VPN entirely on devices where it is not required eliminates exposure, as devices that never had SSL-VPN enabled are not impacted (FortiGuard Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Fortinet products, including CVE-2025-68686, recommending prompt patching (CIS Advisory). Belgium's Centre for Cybersecurity (CCB) also issued a warning urging organizations to patch Fortinet products immediately. The reporting researcher, Peter Gabaldon of ITRESIT, published a technical blog post detailing the symlink persistence patch bypass mechanism (ITRESIT Labs). Community interest was moderate, with the vulnerability appearing in threat aggregators and security feeds shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."