Fortinet FortiOS Patch Bypass Lets Attackers Restore Symlink Persistence (CVE-2025-68686, CISA KEV)
What Happened
Fortinet has disclosed CVE-2025-68686, an exposure of sensitive information to an unauthorized actor vulnerability in FortiOS. According to the FortiGuard PSIRT advisory (FG-IR-25-934), the flaw allows a remote, unauthenticated attacker to bypass the patch Fortinet released for the earlier symbolic link persistency mechanism seen in prior post-exploitation cases, via crafted HTTP requests. CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. It is not yet publicly known whether ransomware operators are leveraging this issue.
Why It Matters
This is a bypass of a fix for a persistence technique, not a fresh initial-access vector on its own: per Fortinet's own advisory, an attacker must already have compromised the device via another vulnerability at the filesystem level before this bug becomes relevant. That makes it most significant for organizations that were previously targeted by the symlink-persistence campaign and assumed the earlier patch had closed the door. If this bypass is being actively exploited, devices believed to be remediated may still be susceptible to attackers re-establishing footholds through crafted HTTP requests.
What Defenders Should Do Now
- Apply Fortinet's updated fix for FG-IR-25-934 as soon as it is available for your FortiOS version, in addition to any prior symlink-persistence patches.
- Treat this as a signal to re-verify FortiOS devices that were previously flagged or remediated for symlink-based persistence — a prior clean bill of health may no longer hold.
- Hunt for anomalous or unexpected symbolic links on FortiOS filesystems, and review HTTP request logs to the management/administrative interfaces for irregular or malformed patterns.
- Audit for indicators of prior compromise (the advisory implies initial filesystem-level access via a separate vulnerability), since this bypass alone is not the initial entry point.
- Restrict management-plane exposure to the internet where feasible and monitor CISA KEV updates for further guidance on this CVE.
Developing Intel
This entry was just added to the CISA KEV catalog and details are still emerging; full technical specifics from Fortinet may evolve. For the authoritative advisory and remediation guidance, see Fortinet's PSIRT bulletin: FG-IR-25-934.