Threat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mapping

Unattributed — CISA states active exploitation without naming an actorhigh

FortiOS: the patch meant to shut the back door was bypassed — and it is now in KEV

On 27 July 2026 CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog, with a remediation deadline of 10 August. The flaw does not open a door: it reopens one that was believed closed. It bypasses the fix Fortinet developed against the symbolic-link persistence mechanism observed in some post-exploitation cases, allowing a remote, unauthenticated attacker to keep reading files on a device that was compromised earlier. Fortinet rates it **medium**, CVSS 5.3, and its advisory page still shows "Known Exploited: No". CISA says otherwise. Both statements are documented, and the gap between them is the real subject of this dossier.

A flaw that presupposes another flaw

Almost every vulnerability we cover has the same shape: someone who should not get in, gets in. Not this one. CVE-2025-68686 assumes the attacker is already inside — and asks a different question: when you cleaned that device, what stayed behind?

The context is FortiGate appliances compromised through known flaws and then "fixed". In some of those cases the attackers had left behind a persistence mechanism built on a symbolic link: a link planted in the device filesystem that kept exposing configuration files even after the entry vulnerability had been patched. Fortinet developed a specific patch against that mechanism.

That patch can be bypassed. That is exactly what the title of the Fortinet advisory says: SSL-VPN Symlink Persistence Patch Bypass.

  1. 01
    Initial compromise
    through another vulnerability, at filesystem level
  2. 02
    Symbolic link planted
    read-only persistence, survives the entry-point patch
  3. 03
    CVE-2025-68686
    crafted HTTP requests bypass the anti-symlink fix as well

What the vendor says, verbatim

Advisory FG-IR-25-934 classifies the flaw as Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), component SSL-VPN, unauthenticated attack type, impact information disclosure. Score CVSSv3 5.3, severity medium. Published 10 February 2026, updated 12 March 2026 with IPS package information.

Affected versions and fixes:

FortiOS 7.6
7.6.0 → 7.6.1
upgrade to 7.6.2 or above
FortiOS 7.4
7.4.0 → 7.4.6
upgrade to 7.4.7 or above
FortiOS 7.2 · 7.0 · 6.4
all versions
migrate to a fixed release

Two vendor clarifications change the risk picture considerably, and they should be read together.

First: "this vulnerability can only be abused as a consequence of a threat actor exploiting a known vulnerability to implement read-only access to vulnerable FortiGate devices, at file system level". It is not an entry point: it is a tail.

Second: "products that never had SSL-VPN enabled are not impacted by this issue". That is the fastest filter you have tonight.

A virtual patch also exists, named FG-VD-60389.0day, available in FMWP database update 26.033. The issue was reported under responsible disclosure by Peter Gabaldon (ITRESIT).

The uncomfortable part: 5.3 versus "actively exploited"

On Fortinet's PSIRT page, at the time of this analysis, the Known Exploited field reads No. In CISA's KEV catalog the same CVE has been listed since 27 July 2026, and there is only one criterion for entry: evidence of active exploitation. The remediation deadline for US federal civilian agencies is 10 August 2026, with the required action tied to directive BOD 26-04 and its Forensics Triage Requirements. Known use in ransomware campaigns is marked Unknown.

We are not resolving that contradiction, and we will not pretend we can. There are at least two readings: the vendor page may simply not have been updated after the KEV listing (its last stated update is 12 March), or vendor and agency are weighing different evidence. What can be said with certainty is that two primary sources currently disagree about the same identifier, and one of them imposes an operational deadline.

There is, however, a more useful way to read the 5.3. That score measures a vulnerability in isolation: high attack complexity, confidentiality impact only, no write, no availability impact. But this flaw by definition does not exist in isolation: it only lives on devices that were already compromised. In the real chain its value is not "how much damage it does", it is "how long the attacker keeps reading after you believe you evicted them". A base CVSS score does not capture that.

What the story is actually about

The operational lesson concerns Fortinet no more than it concerns anyone running an edge appliance. It is about the difference between patching and eradicating.

Applying a patch closes the vulnerability that allowed entry. It does not remove what the attacker left: files, links, accounts, keys, sessions. On a closed appliance — where you do not install an EDR, do not freely inspect the filesystem, do not run forensics with your usual tooling — that distinction is particularly cruel, because the visible part of the work (the version number going up) is also the most reassuring part.

  1. 10 February 2026
    Fortinet advisory

    FG-IR-25-934 published: medium severity, CVSS 5.3.

  2. 12 March 2026
    Update

    IPS package information added.

  3. 27 July 2026
    Added to KEV

    CISA lists it among actively exploited vulnerabilities.

  4. 10 August 2026
    Deadline

    Remediation due date for US federal agencies under BOD 26-04.

What to do, in order of urgency

First, the one-minute filter. If SSL-VPN was never enabled on that device, this CVE does not affect you. Verify it, do not recall it.

Second, upgrade. 7.6.2 or above, 7.4.7 or above. If you are on 7.2, 7.0 or 6.4 there is no fixed release in your branch: the path is migration, and those branches are accumulating far more debt than this one item. Where upgrading is not immediate, the virtual patch FG-VD-60389.0day (FMWP 26.033) is containment, not a fix.

Third, and this is the real work: ask whether that device was ever compromised. This flaw is only useful to an attacker in that case. If your FortiGate was caught in one of the known campaigns against Fortinet SSL-VPNs — and there have been several over the past two years — then tonight's upgrade does not close the story. It calls for a review of configuration files, local credentials and what was actually rotated after the incident, not before.

Fourth: rotate as if you had lost your configuration files. The stated impact is information disclosure. On a VPN concentrator, "information" means configuration, and configuration contains much of what is needed to come back.

A note on sourcing, because here it matters more than usual: the technical details, versions and score come from the Fortinet advisory; the active-exploitation status and the deadline come from CISA's KEV catalog. The two sources disagree on the "exploited" field, and we wrote that down instead of picking whichever reads better. If the vendor page is updated, this dossier will be updated with it.

More dossiers