← Back to browse · API

CVE-2025-68686

Severity
MEDIUM
CVSS
5.3
EPSS
0.01264
Risk score
46.64
CISA KEV
Yes
PoC
No
Published
2026-07-27
Modified
2026-07-27
First seen
2026-08-05
Aliases
EUVD-2025-207440, GHSA-839G-M33X-3W78
Products
Fortinet:FortiOS, Fortinet:FortiOS 6.4.0 ≤6.4.16, Fortinet:FortiOS 7.0.0 ≤7.0.19, Fortinet:FortiOS 7.2.0 ≤7.2.13, Fortinet:FortiOS 7.4.0 ≤7.4.6, Fortinet:FortiOS 7.6.0 ≤7.6.1, fortinet:fortios
Sources
nvd CVE-2025-68686
cisa.gov CVE-2025-68686
euvd EUVD-2025-207440

Description

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

References