Fortinet FortiOS Patch-Bypass Vulnerability Added to CISA’s Known Exploited List

A newly catalogued flaw in FortiOS allows post-compromise attackers to circumvent a previously deployed patch, extending their access through crafted HTTP requests.

AI-generated illustration depicting vulnerability for the story: Fortinet FortiOS Patch-Bypass Vulnerability Added to CISA's Known Exploited List

Summary

  • CISA has added CVE-2025-68686 to its Known Exploited Vulnerabilities catalogue, with a remediation deadline of 10 August 2026.
  • The vulnerability affects Fortinet FortiOS and enables a remote, unauthenticated attacker to bypass a patch designed to address symbolic link persistence — but only after the device has already been compromised through a separate vulnerability.
  • Exploitation requires prior filesystem-level access, meaning this flaw is most relevant to organisations that may already have a compromised FortiOS device in their environment.
  • CISA’s required action includes applying vendor mitigations, conducting forensic triage, and evaluating whether affected assets are internet-exposed.
  • Organisations unable to apply mitigations are directed to discontinue use of the product.

What the Vulnerability Is

CVE-2025-68686 is classified as an exposure of sensitive information to an unauthorised actor within Fortinet FortiOS. Its specific character makes it somewhat unusual: the flaw does not enable initial access on its own. Instead, it allows an attacker who has already established a foothold at the filesystem level — through a separate, unspecified vulnerability — to bypass the remediation Fortinet had previously deployed against a symbolic link persistence mechanism. In other words, an earlier fix for a known post-exploitation technique can be circumvented by sending crafted HTTP requests.

The Persistence Problem

Symbolic link persistence is a technique observed in post-exploitation scenarios involving network appliances. Once an attacker gains access, planting symbolic links can allow them to maintain that access even after reboots or partial remediation efforts. Fortinet had previously developed a patch targeting this specific behaviour. This new vulnerability undermines that patch, meaning attackers with prior access could re-establish or maintain persistence despite an organisation believing it had closed that avenue. The practical implication is that devices considered remediated may not be.

Who Is at Risk

The risk profile here is specific but serious. Organisations running Fortinet FortiOS at the perimeter — as is common given FortiGate’s widespread deployment as a next-generation firewall and VPN gateway — that have experienced or suspect any prior compromise are most exposed. Because the attacker requires existing filesystem-level access, the vulnerability is not a direct entry point. However, given the well-documented history of FortiOS devices being targeted by sophisticated threat actors, the assumption that no prior compromise has occurred should be made carefully and with supporting evidence. Organisations without strong forensic visibility into their FortiOS deployments are in a weaker position to make that assessment confidently.

CISA’s Expectations

CISA’s addition of this CVE to the Known Exploited Vulnerabilities catalogue signals that the agency has determined the vulnerability poses sufficient real-world risk to warrant mandatory remediation for US federal civilian agencies under Binding Operational Directive 26-04. The required actions go beyond a straightforward patch: CISA specifically calls out forensic triage requirements alongside the standard patching guidance. This dual expectation — patch and investigate — reflects the post-exploitation nature of the flaw. The remediation deadline is set for 10 August 2026. For cloud-hosted deployments of affected products, BOD 26-04 cloud guidance applies separately.

What Is Still Unknown

The source material does not identify specific threat actors or campaigns exploiting this vulnerability, nor does it detail which FortiOS versions are affected beyond the general product reference. Fortinet’s own advisory detail, including affected version ranges and precise mitigation steps, would need to be consulted directly. Organisations should not wait for that confirmation before initiating their assessment.

Why it matters

For CISOs, the key risk framing here is not the vulnerability in isolation but what it implies about the state of devices in your environment. If a FortiOS appliance was previously compromised — and FortiOS devices have been a persistent target for nation-state and financially motivated actors — then a patch your team applied to address persistence may not have achieved what you believed it did. This flaw resets the confidence baseline. The CISA-mandated forensic triage requirement is worth taking seriously even outside the federal context: it is an acknowledgement that patching alone is insufficient and that active investigation for indicators of prior compromise is warranted. Boards and audit committees will reasonably ask whether affected perimeter devices have been verified clean, not merely patched.

What to do now

  • Apply Fortinet’s available mitigations for CVE-2025-68686 in line with vendor instructions and CISA’s BOD 26-04 guidance.
  • Evaluate each affected FortiOS asset for internet exposure and prioritise accordingly.
  • Conduct forensic triage of FortiOS devices as directed by CISA’s Forensics Triage Requirements referenced in the KEV entry.
  • For FortiOS instances deployed in cloud environments, apply the relevant BOD 26-04 cloud-specific guidance.
  • If mitigations cannot be applied, assess whether discontinuing use of the affected product is operationally feasible, as directed by CISA.
  • Do not assume devices are clean based on prior remediation activity alone — prior patches addressing symbolic link persistence may have been bypassed.

Sources