PT-2026-7277 · Fortinet · Fortios

CVE-2025-68686

·

Published

2026-02-10

·

Updated

2026-09-10

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.6.0 through 7.6.1 FortiOS versions 7.4.0 through 7.4.6 FortiOS 7.2 (affected versions not specified) FortiOS 7.0 (affected versions not specified) FortiOS 6.4 (affected versions not specified)
Description An exposure of sensitive information to an unauthorized actor exists in the SSL-VPN function. This issue allows a remote unauthenticated attacker to bypass a previously developed patch for the symbolic link persistency mechanism used in some post-exploit scenarios by sending crafted HTTP requests. To exploit this, an attacker must have already compromised the product through a separate vulnerability at the filesystem level. Active exploitation of this issue has been observed in the wild.
Recommendations Update FortiOS versions 7.6.0 through 7.6.1 to a newer version. Update FortiOS versions 7.4.0 through 7.4.6 to a newer version. Update FortiOS 7.2 to a newer version. Update FortiOS 7.0 to a newer version. Update FortiOS 6.4 to a newer version.

Fix

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01823
CVE-2025-68686

Affected Products

Fortios