---
schema: 1
kind: vulnerability
title: "CVE-2025-68686 — FortiOS SSL-VPN: the fix for the symlink-persistence technique is itself bypassable, and CISA now lists it as exploited"
headline: "CISA KEV-lists a FortiOS flaw that defeats Fortinet's own fix for SSL-VPN symlink persistence"
summary: >
  CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog on 2026-07-27, confirming
  in-the-wild abuse of a FortiOS SSL-VPN flaw that lets a remote unauthenticated attacker bypass the patch
  Fortinet built for the symbolic-link persistence mechanism seen in earlier FortiGate post-exploitation
  cases. It is not an initial-access vector — Fortinet states an attacker must already have compromised the
  device at filesystem level through another vulnerability — which is exactly why it matters: any FortiGate
  that was exposed to an earlier root-filesystem CVE and then "remediated" may still be readable. Fixed in
  FortiOS 7.6.2 and 7.4.7; 7.2, 7.0 and 6.4 are affected in all versions and require migration to a
  supported release.
discovered_at: "2026-07-28T04:47:00Z"
event_date: "2026-07-27"
run_id: 2026-07-28T0409Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, actively-exploited, cisa-kev, info-disclosure, pre-auth, patch-available]
regions: [global]
sectors: [public-sector, technology]
entities: []
techniques: [T1190, T1211, T1005]
affected_products: ["Fortinet FortiOS"]
cves:
  - id: CVE-2025-68686
    cvss: "5.9"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available, mitigation-only]
    affected: "FortiOS 7.6.0 through 7.6.1; 7.4.0 through 7.4.6; 7.2, 7.0 and 6.4 in all versions. Fortinet states devices that never had SSL-VPN enabled are not impacted."
    fixed: "Upgrade to FortiOS 7.6.2 or above (7.6 branch) or 7.4.7 or above (7.4 branch); for 7.2, 7.0 and 6.4 Fortinet's remediation is migration to a fixed release, as no fixed build exists on those branches. A virtual patch shipped in FMWP database update 26.033."
sources:
  - url: "https://fortiguard.fortinet.com/psirt/FG-IR-25-934"
    publisher: "Fortinet PSIRT (FG-IR-25-934)"
    date: "2026-02-10"
    role: primary
  - url: "https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog"
    publisher: "CISA"
    date: "2026-07-27"
    role: primary
  - url: "https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity"
    publisher: "Fortinet PSIRT (blog)"
    date: "2025-04-10"
    role: corroborating
closed_sources: []
evidence:
  - quote: "An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level."
    publisher: "Fortinet PSIRT (FG-IR-25-934)"
  - quote: "This vulnerability can only be abused as a consequence of a threat actor exploiting a known vulnerability to implement read-only access to vulnerable FortiGate devices, at file system level."
    publisher: "Fortinet PSIRT (FG-IR-25-934)"
  - quote: "Products that never had SSL-VPN enabled, are not impacted by this issue."
    publisher: "Fortinet PSIRT (FG-IR-25-934)"
  - quote: "This was achieved via creating a symbolic link connecting the user filesystem and the root filesystem in a folder used to serve language files for the SSL-VPN."
    publisher: "Fortinet PSIRT (blog)"
verification: multi-source
sourcing_note: "Fortinet is the CNA and the primary disclosing party for its own product (reliability A); CISA's KEV addition is an independent government assertion of in-the-wild exploitation, giving credibility 1. One scoring subtlety and one status discrepancy are worth recording. On scoring, the two figures in circulation are not a contradiction: the 5.3 displayed on the FortiGuard advisory hyperlinks to the vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N with the temporal metrics E:P/RL:O/RC:C appended, so 5.3 is the temporal-adjusted score of the same 5.9 base vector Fortinet submitted as CNA. This entry carries the 5.9 base score, because every other CVE record in this store carries a base score and mixing a temporal one in would break comparison; the temporal figure the vendor page shows is recorded here so a reader who sees 5.3 on the advisory can reconcile the two. Second, exploitation status: as fetched on 2026-07-28 the FortiGuard advisory still shows 'Known Exploited: No' and a timeline whose last update is 2026-03-12, months before CISA's KEV addition — the vendor field appears simply not to have been refreshed, and CISA's listing is the current exploitation signal."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Enumerate every FortiGate that was running SSL-VPN while exposed to an earlier root-filesystem FortiOS vulnerability and check the SSL-VPN language-file directories for symbolic links pointing outside the user filesystem — do this regardless of when the device was patched, because this flaw specifically defeats the fix that was supposed to close that persistence path."
  - "Move FortiOS 7.2, 7.0 and 6.4 devices onto a supported branch: those trains are affected in all versions and have no fixed build, so upgrading within the branch does not remediate."
migrated_from: null
---

CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog on 2026-07-27 ([CISA, 2026-07-27](https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog)). The flaw itself is not new — Fortinet published FG-IR-25-934 on 2026-02-10 — but the KEV listing is the first assertion that it is being used against devices in the field, and it changes the disposition of a class of FortiGate estates that were considered remediated.

What the flaw does is narrow and precisely stated: it is an exposure of sensitive information (CWE-200) in FortiOS SSL-VPN that "may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests", and Fortinet is explicit that "[a]n attacker would need first to have compromised the product via another vulnerability, at filesystem level" ([Fortinet PSIRT, 2026-02-10](https://fortiguard.fortinet.com/psirt/FG-IR-25-934)). In other words it is a persistence-and-evasion primitive layered on top of an earlier intrusion, not a way in. The operational consequence runs the other way from the modest severity score: the symlink technique it restores is the one Fortinet documented in April 2025, where an attacker who had reached the root filesystem achieved persistence "via creating a symbolic link connecting the user filesystem and the root filesystem in a folder used to serve language files for the SSL-VPN" — so that "even if the customer device was updated with FortiOS versions that addressed the original vulnerabilities, this symbolic link may have been left behind, allowing the threat actor to maintain read-only access to files on the device's file system, which may include configurations" ([Fortinet PSIRT, 2025-04-10](https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity)). Fortinet's fix for that technique is what this CVE defeats, so a FortiGate whose response consisted of "patch the CVE, confirm the symlink fix is in place, close the ticket" may not in fact have evicted the attacker.

Scope is broad on the older branches. Fortinet lists FortiOS 7.6.0 through 7.6.1 (fixed in 7.6.2), 7.4.0 through 7.4.6 (fixed in 7.4.7), and 7.2, 7.0 and 6.4 as affected in all versions with migration to a fixed release as the only remediation; a virtual patch is available in FMWP database update 26.033, and devices that never had SSL-VPN enabled are out of scope ([Fortinet PSIRT, 2026-02-10](https://fortiguard.fortinet.com/psirt/FG-IR-25-934)).

Detection is filesystem-integrity work on the appliance rather than network detection, because the abuse rides ordinary HTTPS to the SSL-VPN web listener and will not look anomalous in flow telemetry. The concrete hunt is an inventory question first: which FortiGates ran SSL-VPN while exposed to an earlier root-filesystem flaw, and of those, which show symbolic links in the SSL-VPN language-file directories that resolve outside the user filesystem, or drift in the language-pack files against a known-good image — that directory being the location Fortinet named when it first documented the technique ([Fortinet PSIRT, 2025-04-10](https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity)). Because the read access this restores is passive, the absence of outbound anomalies is not evidence of cleanliness — the discriminator is the presence of the link itself, not any traffic it produces. For estates that cannot immediately move off 7.2, 7.0 or 6.4, disabling SSL-VPN where it is not operationally required removes the component entirely, which is stronger than the virtual patch and follows directly from Fortinet's own scoping note that non-SSL-VPN deployments are unaffected.
