Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-28 ยท updated: 2026-07-28 ยท tags: [cve, kev] ยท confidence: high ยท severity: medium ยท affected_sectors: [technology] ยท au_impact: false

CVE-2025-68686

Summary

An unauthenticated HTTP-request bypass vulnerability targeting Fortinet FortiOS symbolic link persistency patches within compromised environments.

Details

This vulnerability (tracked as CVE-2025-68686, CVSS 5.3 Medium) affects Fortinet FortiOS. It allows unauthenticated remote attackers to bypass previous symbolic link persistency patches inside compromised environments via crafted HTTP requests.

Exploitation in the Wild

On July 27, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. Under Binding Operational Directive (BOD) 26-04, federal civilian agencies must remediate this flaw immediately to defend their edge networks.

The decay of edge network perimeters is highlighted by the exploitation of such symbolic link persistency bypasses, allowing persistent footholds within compromised security systems.

Related Pages