Emergency Security Bulletin: SSL-VPN Symlink Persistence Patch Bypass in FortiOS

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

CVE-2025-68686 is an information disclosure and security patch bypass vulnerability affecting the SSL-VPN functionality in FortiOS.

The vulnerability may allow an unauthenticated attacker to bypass a previously released patch designed to prevent a symbolic-link persistence mechanism used in earlier attacks. Exploitation requires the FortiOS device to have already been compromised at the filesystem level through another vulnerability.

Successful exploitation may allow an attacker to retain or regain access to sensitive information despite prior remediation efforts. Fortinet has confirmed active exploitation in the wild, and CISA has added CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) Catalog.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

SSL-VPN Symlink Persistence Patch Bypass in FortiOS


Identifier: CVE-2025-68686
PoC or Exploitation:

CVE-2025-68686 is actively exploited in the wild.
 
CISA added the vulnerability to the Known Exploited Vulnerabilities Catalog.


CVSS Score:  5.9 (Medium, CVSS v3.1 base score)

Update / Patch:

Fortinet has released fixed FortiOS versions addressing the vulnerability.

Affected versions include:

FortiOS 7.6.0 through 7.6.1FortiOS 7.4.0 through 7.4.6FortiOS 7.2, all versionsFortiOS 7.0, all versionsFortiOS 6.4, all versions

Fixed versions and remediation include:

  • FortiOS 7.6Upgrade to FortiOS 7.6.2 or later.

  • FortiOS 7.4Upgrade to FortiOS 7.4.7 or later.

  • FortiOS 7.2Migrate to a fixed release.

  • FortiOS 7.0Migrate to a fixed release.

  • FortiOS 6.4Migrate to a fixed release.

Fortinet advisory and remediation guidance: https://fortiguard.fortinet.com/psirt/FG-IR-25-934

Description:

CVE-2025-68686 is an information-disclosure and security-patch-bypass vulnerability affecting the SSL-VPN functionality in FortiOS.
 
The vulnerability may allow an unauthenticated attacker to bypass a patch developed to prevent a symbolic-link persistence mechanism observed during previous attacks. Successful use requires the FortiOS device to have already been compromised at the filesystem level through another vulnerability.
 
This condition may allow an attacker who previously compromised a device to retain or regain access to sensitive information despite earlier remediation.  

 

Mitigation Recommendation:

Migrate FortiOS 7.6,7.4, 7.2, 7.0, and 6.4 deployments to a vendor-supported fixed release.
 
Identify all internet-facing FortiGate devices and verify their installed FortiOS versions.
 
Investigate affected devices for unauthorized filesystem changes, unexpected symbolic links, anomalous SSL-VPN activity, unauthorized configuration changes, and suspicious administrative access.
 
If compromise is identified, isolate the affected device, preserve relevant forensic evidence, remove persistence mechanisms, rotate potentially exposed administrative and VPN credentials, and rebuild or restore the appliance from a trusted configuration where necessary.