Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
PortSwigger Introduces Burp AT Agentic AI for Human-Led Web Pentesting
July 28, 2026
Critical FFmpeg Vulnerabilities Let Attackers Corrupt Memory
July 28, 2026
Microsoft Teams Vishing Attack Exploits Quick Assist for GoGRPC Backdoor
July 28, 2026
Home/CyberSecurity News/CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks
CyberSecurity News

CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks

Key Takeaways The Cybersecurity and Infrastructure Security Agency (CISA) has added a Fortinet FortiOS vulnerability, CVE-2025-68686, to its Known Exploited Vulnerabilities (KEV) catalog due to...

Jennifer sherman
Jennifer sherman
July 28, 2026 3 Min Read
3 0

Key Takeaways

  • The Cybersecurity and Infrastructure Security Agency (CISA) has added a Fortinet FortiOS vulnerability, CVE-2025-68686, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation.
  • This flaw impacts FortiOS, the operating system powering FortiGate firewalls and other Fortinet security products, and is categorized as an information exposure issue (CWE-200).
  • Exploitation allows a remote, unauthenticated attacker to bypass a patch designed to prevent a symbolic link persistence technique, but only if the attacker has already achieved filesystem-level access through a separate compromise.
  • While a patch bypass, it requires prior compromise, making detection of initial intrusion critical.
  • Federal agencies must apply mitigations by August 10, 2026, and all organizations are urged to prioritize addressing this vulnerability, especially on internet-exposed devices.

CISA Flags Actively Exploited Fortinet FortiOS Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert, incorporating the Fortinet FortiOS vulnerability identified as CVE-2025-68686 into its Known Exploited Vulnerabilities (KEV) catalog. This action follows confirmation that the flaw is actively being leveraged in real-world attacks, elevating its urgency for cybersecurity defenders.

Table Of Content

  • Key Takeaways
  • CISA Flags Actively Exploited Fortinet FortiOS Vulnerability
  • Understanding CVE-2025-68686
  • Implications of the Patch Bypass
  • What You Should Do

Understanding CVE-2025-68686

CVE-2025-68686 affects Fortinet FortiOS, the core operating system utilized across the company’s FortiGate firewall series and other security solutions. The vulnerability is classified under CWE-200, indicating an exposure of sensitive information to an unauthorized actor.

According to CISA’s assessment, this vulnerability enables a remote, unauthenticated attacker to circumvent a security patch. This patch was specifically designed to mitigate a symbolic link persistence technique. Attackers can exploit this issue by transmitting specially crafted HTTP requests to a vulnerable device.

A crucial prerequisite for successful exploitation, however, is that the attacker must have already compromised the FortiOS product. This initial breach needs to have granted them filesystem-level access to the device through an unrelated vulnerability.

Implications of the Patch Bypass

In scenarios where an attacker has already gained a foothold, CVE-2025-68686 becomes a critical tool. It can help threat actors evade or bypass existing protections that were put in place to address post-exploitation persistence mechanisms observed in previous incidents.

Symbolic links, often referred to as symlinks, are file system references that direct to another file or directory. Malicious actors frequently misuse these after gaining initial access to a device. Their objectives can include maintaining persistence within the network, accessing protected files, or disrupting remediation efforts by security teams.

Consequently, a patch bypass involving symbolic links poses significant risks for organizations. It can create a false sense of security, leading them to believe that a previously compromised appliance has been fully secured, when in reality, an attacker’s persistence mechanisms may still be active or easily re-established.

While CISA has not yet confirmed any association between CVE-2025-68686 and ransomware campaigns, its designation as an actively exploited vulnerability necessitates immediate attention. Organizations must treat this as a high-priority security concern, particularly for FortiOS appliances that are exposed to the public internet.

What You Should Do

  • Federal Civilian Executive Branch agencies are mandated to implement the necessary mitigations for CVE-2025-68686 by August 10, 2026. CISA has instructed affected organizations to adhere to Fortinet’s vendor guidance and comply with Binding Operational Directive 26-04, which prioritizes security updates based on risk.
  • All organizations should conduct an inventory of their deployed FortiOS assets. Determine if any management interfaces or VPN services are internet-facing, as these are higher-risk targets. Regularly review Fortinet advisories for available updates or mitigations.
  • Given that this vulnerability requires prior filesystem-level access, security teams should proactively investigate devices for any signs of earlier compromise.
  • CISA further recommends following its Forensics Triage Requirements when responding to potentially compromised appliances. This includes a thorough review of administrative login records, configuration changes, suspicious HTTP requests, newly created files, unauthorized user accounts, and any unexpected persistence artifacts.
  • If no mitigation is immediately available, organizations should consider removing affected systems from internet exposure or discontinuing their use until a secure remediation path is established. The inclusion of this vulnerability in the KEV catalog emphasizes that perimeter appliances remain a frequent target for threat actors seeking persistent access into enterprise networks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

DCSync Attacks Steal Active Directory Password Hashes Silently

Next Post

Operation STANDOFF Malware Hides C2 Traffic with GitHub Redirects

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DCSync Attacks Steal Active Directory Password Hashes Silently
July 28, 2026
OpenAI CEO Sam Altman: AI Has Reached Singularity, Systems Improve Themselves
July 28, 2026
Europol Dismantles Online Network Recruiting Teen Hackers for Extortion
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us