7 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2025-68686 is an information disclosure and security patch bypass vulnerability affecting the SSL-VPN functionality in FortiOS.
The vulnerability may allow an unauthenticated attacker to bypass a previously released patch designed to prevent a symbolic-link persistence mechanism used in earlier attacks. Exploitation requires the FortiOS device to have already been compromised at the filesystem level through another vulnerability.
Successful exploitation may allow an attacker to retain or regain access to sensitive information despite prior remediation efforts. Fortinet has confirmed active exploitation in the wild, and CISA has added CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) Catalog.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
SSL-VPN Symlink Persistence Patch Bypass in FortiOS
Identifier: CVE-2025-68686
PoC or Exploitation:
CVSS Score: 5.9 (Medium, CVSS v3.1 base score)
Update / Patch:
Fortinet has released fixed FortiOS versions addressing the vulnerability.
Affected versions include:
FortiOS 7.6.0 through 7.6.1FortiOS 7.4.0 through 7.4.6FortiOS 7.2, all versionsFortiOS 7.0, all versionsFortiOS 6.4, all versions
Fixed versions and remediation include:
-
FortiOS 7.6Upgrade to FortiOS 7.6.2 or later.
-
FortiOS 7.4Upgrade to FortiOS 7.4.7 or later.
-
FortiOS 7.2Migrate to a fixed release.
-
FortiOS 7.0Migrate to a fixed release.
-
FortiOS 6.4Migrate to a fixed release.
Fortinet advisory and remediation guidance: https://fortiguard.fortinet.com/psirt/FG-IR-25-934
Description:
Mitigation Recommendation: