Status: KEV
| Advisory ID: CVE-2025-68686
Key Details
| CVE | CVE-2025-68686 |
| Vulnerability Name | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability |
| Affected products | Fortinet FortiOS |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-07-27. |
| Exploitation prediction (EPSS) | 29.60% probability of exploitation in the next 30 days (98% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-08-10 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | Core Infrastructure |
| Sectors | Multi-sector |
What to Know
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
What to Do
Monitor Fortinet's web page for any future patch releases.
References
KEV Required Action