CVE-2025-68686

● KEV MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, F...

Affects 1 product across 3 vendors.

BCS4.23
CVSS 3.15.9
EPSS0.5%
Percentile38th
PatchUnknown
KEV Added2026-07-27
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-200: Exposure of Sensitive Information

Application reveals restricted data such as system internals, credentials, or user data to unauthorized actors.

Related Attack Patterns (CAPEC)
CAPEC-13 Subverting Environment Variable Values
via CWE-200
CAPEC-59 Session Credential Falsification through Prediction
via CWE-200
CAPEC-60 Reusing Session IDs (aka Session Replay)
via CWE-200
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-200
CAPEC-285 ICMP Echo Request Ping
via CWE-200
Show all 59

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in Fortinet FortiOS allows a remote unauthenticated attacker to bypass a patch related to the symbolic link persistency mechanism, potentially leading to unauthorized access to sensitive information.

BSID: BS-2026-GLOBAL-275885-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-68686?
A vulnerability in Fortinet FortiOS allows a remote unauthenticated attacker to bypass a patch related to the symbolic link persistency mechanism, potentially leading to unauthorized access to sensitive information.
What is the CVSS score for CVE-2025-68686?
CVE-2025-68686 has CVSS 5.9 (Medium). Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. EPSS: 0.5%.
Is CVE-2025-68686 actively exploited?
Yes. CVE-2025-68686 is in the CISA KEV catalog (added 2026-07-27). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2025-68686?
Priority: HIGH. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-934 PSIRT: [email protected]
What systems are affected by CVE-2025-68686?
CVE-2025-68686 affects: Fortinet, Fujitsu-Siemens, Siemens.
Vulnerability Details
CVE IDCVE-2025-68686
BSIDBS-2026-GLOBAL-275885-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Published2026-02-10
Last Modified2026-07-27
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves exploiting a flaw in the symbolic link persistency mechanism, which could be triggered by a remote unauthenticated attacker to bypass security patches and gain unauthorized access to sensitive information.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fortinet Fortios
Fujitsu-Siemens —
Siemens —
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 167 Days
CISA KEV● Active Exploitation Confirmed (added 2026-07-27)
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashe6e7e4b3de4211d447d9d9d73155146fb65ebf8d9511b9abe1bcece71ec3ccfc9c5c6deabb8d64faba514a3c0c27f338ddcb261429d4d0320515e9dac701b5a0
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2023-36554 9.8 A improper access control in Fortinet FortiManager version 7.4.0, version 7.2... CVE-2022-35846 9.8 An improper restriction of excessive authentication attempts vulnerability [C... CVE-2021-24019 9.8 An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS...
View all Fortinet CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2025-68686 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →