CVE-2025-68686
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, F...
Affects 1 product across 3 vendors.
Application reveals restricted data such as system internals, credentials, or user data to unauthorized actors.
Show all 59
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A vulnerability in Fortinet FortiOS allows a remote unauthenticated attacker to bypass a patch related to the symbolic link persistency mechanism, potentially leading to unauthorized access to sensitive information.
BSID: BS-2026-GLOBAL-275885-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-68686?
What is the CVSS score for CVE-2025-68686?
Is CVE-2025-68686 actively exploited?
How do I remediate CVE-2025-68686?
What systems are affected by CVE-2025-68686?
| CVE ID | CVE-2025-68686 |
|---|---|
| BSID | BS-2026-GLOBAL-275885-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Published | 2026-02-10 |
| Last Modified | 2026-07-27 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Domains | |
| Source | NVD |
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Source: NIST NVD / MITRE CVE Database
The attack vector involves exploiting a flaw in the symbolic link persistency mechanism, which could be triggered by a remote unauthenticated attacker to bypass security patches and gain unauthorized access to sensitive information.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fortinet | Fortios | — |
| Fujitsu-Siemens | — | — |
| Siemens | — | — |
| CISA KEV | ● Active Exploitation Confirmed (added 2026-07-27) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | e6e7e4b3de4211d447d9d9d73155146fb65ebf8d9511b9abe1bcece71ec3ccfc9c5c6deabb8d64faba514a3c0c27f338ddcb261429d4d0320515e9dac701b5a0 |
This Vulnerability Is Being Actively Exploited
CVE-2025-68686 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →