PT-2026-7277 · Fortinet · Fortios
CVE-2025-68686
·
Published
2026-02-10
·
Updated
2026-09-10
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 7.6.0 through 7.6.1
FortiOS versions 7.4.0 through 7.4.6
FortiOS 7.2 (affected versions not specified)
FortiOS 7.0 (affected versions not specified)
FortiOS 6.4 (affected versions not specified)
Description
An exposure of sensitive information to an unauthorized actor exists in the SSL-VPN function. This issue allows a remote unauthenticated attacker to bypass a previously developed patch for the symbolic link persistency mechanism used in some post-exploit scenarios by sending crafted HTTP requests. To exploit this, an attacker must have already compromised the product through a separate vulnerability at the filesystem level. Active exploitation of this issue has been observed in the wild.
Recommendations
Update FortiOS versions 7.6.0 through 7.6.1 to a newer version.
Update FortiOS versions 7.4.0 through 7.4.6 to a newer version.
Update FortiOS 7.2 to a newer version.
Update FortiOS 7.0 to a newer version.
Update FortiOS 6.4 to a newer version.
Fix
RCE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios