CISA has added the actively exploited Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active attacks.
The vulnerability affects Fortinet FortiOS, the operating system used across FortiGate firewalls and other Fortinet security products. It is classified as an exposure of sensitive information to an unauthorized actor issue, mapped to CWE-200.
According to CISA, the flaw could allow a remote, unauthenticated attacker to bypass a patch designed to prevent a symbolic link persistence technique. Attackers can exploit the issue by sending specially crafted HTTP requests to a vulnerable device.
However, successful exploitation has an important condition. The attacker must have already compromised the FortiOS product through a separate vulnerability and obtained filesystem-level access.
Fortinet FortiOS Vulnerability Exploited
In this scenario, CVE-2025-68686 may help the attacker evade or bypass protections introduced to address persistence mechanisms seen in previous post-exploitation incidents.
Symbolic links, also called symlinks, are filesystem references that point to another file or directory. Threat actors may abuse them after gaining access to a device to retain persistence, access protected files, or interfere with remediation steps.
A patch bypass involving symbolic links can therefore create serious risks for organizations that believe a previously compromised appliance has been fully secured.
CISA has not confirmed whether CVE-2025-68686 has been used in ransomware campaigns. Nevertheless, the active-exploitation designation means organizations should treat the vulnerability as a high-priority security issue, particularly when FortiOS appliances are exposed to the internet.
Federal Civilian Executive Branch agencies must apply the required mitigations by August 10, 2026. CISA has directed affected organizations to follow Fortinet’s vendor guidance and comply with Binding Operational Directive 26-04, which prioritizes security updates according to risk.
Organizations should identify all deployed FortiOS assets, determine whether management interfaces or VPN services are internet-facing, and review Fortinet advisories for available updates or mitigations.
Security teams should also investigate devices for signs of earlier compromise, because this vulnerability requires prior filesystem-level access. CISA further recommends following its Forensics Triage Requirements when responding to potentially compromised appliances.
This should include reviewing administrative logins, configuration changes, suspicious HTTP requests, newly created files, unauthorized accounts, and unexpected persistence artifacts.
If no mitigation is available, organizations should consider removing affected systems from exposure or discontinuing use until a secure remediation path exists. The KEV addition underscores that perimeter appliances remain a frequent target for threat actors seeking durable access into enterprise networks.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

