Data-leak flaw in FortiGate (CVE-2025-68686) confirmed exploited: check for a prior breach
FortiGate's FortiOS has a confirmed-exploited data-leak flaw (CVE-2025-68686). It cannot break in on its own and only affects already-breached devices. See affected versions, fixes, and how to check for a prior breach.
Table of contents
FortiGate's FortiOS has a confirmed-exploited data-leak flaw (CVE-2025-68686). It cannot break in on its own and only affects already-breached devices. See affected versions, fixes, and how to check for a prior breach.
A weakness has been found in "FortiOS," the base software of FortiGate, the enterprise appliance that companies and governments worldwide place at the edge of their networks. By crafting network requests, an attacker can read sensitive information stored inside the device. The tracking ID is CVE-2025-68686.
On July 27, 2026, the U.S. cybersecurity agency CISA added this flaw to its catalog of vulnerabilities confirmed to be actively exploited (KEV: the list of flaws that CISA has verified are being abused in the real world). A listing on the KEV means this is not a theoretical concern but a flaw used in actual attacks.
That said, this weakness cannot be used to break in from the outside on its own, and its severity is rated only medium. There is no need to panic. But if you run FortiGate, this is a case where you should nail down "Am I affected?" and "What should I check?" Below, we walk through the conditions and the response in order.
The bottom line first: what to check before you panic
For those short on time, here are the key points up front.
This flaw can only be abused on a FortiGate that has already been broken into through a separate vulnerability, leaving the attacker able to touch the device's internal files. It cannot be used on a clean device to attack from the outside using this flaw alone. In other words, the real issue is not a "new entry point" but persistence: whether a previously compromised device is still being quietly read even after patching.
There are two things to do. One is to update to Fortinet's fixed version. The other, and this one matters more, is to check for signs that the device was compromised in the past. If a device is in a state where this flaw applies, that device has most likely already been taken over once. Note that devices with the SSL-VPN feature disabled are not affected.
Overview of the flaw
| Item | Details |
|---|---|
| Tracking ID | CVE-2025-68686 |
| Affected product | Fortinet FortiOS (base software of FortiGate) |
| Affected feature | SSL-VPN (not affected if disabled) |
| Type of flaw | Sensitive information disclosure (bypass of the persistence patch) |
| Severity | Medium (CVSS 5.9 / Fortinet rates 5.3) |
| Prerequisite for abuse | Prior break-in via another flaw required |
| Exploitation status | Active attacks confirmed (KEV listed) |
| U.S. government deadline | August 10, 2026 |
The severity indicator CVSS rates this 5.9 out of 10 in the NVD database run by the U.S. National Institute of Standards and Technology (NIST), and 5.3 in Fortinet's own security advisory. Both put it in the "medium" range. By the numbers, it is not exceptionally high. So why did CISA go out of its way to add it to the KEV? Because this flaw is being used not as an "entry point" but as a "tool to stay hidden after breaking in."
Who targets this, and why
The target is an attacker who has already broken into your company's FortiGate and wants to stay there for a long time. Rather than a broad, opportunistic prankster, think of a targeted attack group that wants a lasting foothold inside a corporate network.
What they do with this flaw is keep quietly reading internal files such as configuration data by sending crafted requests, even after the device has been patched. In 2025, Fortinet distributed a fix to close a "technique for staying on a compromised device," but this flaw slips past that fix. Picture a back door left slightly open even after the administrator is confident the problem has been handled.
What can be lost is not small. The configuration files that can be read may contain credentials for administrators and VPN users, the layout of the internal network, and keys used to encrypt traffic. If these leak, attackers can burrow deeper into internal systems or impersonate legitimate users with stolen credentials. A VPN is the "front door" used to enter a company from outside; having a copy of that key held indefinitely is a quiet but serious risk for any organization. That is exactly why the "check whether you were already breached" step described next is at the heart of the response.
What was actually happening
To understand this flaw, you need to know the chain of attacks around FortiGate that has continued since late 2024.
It began around November 2024, when a separate flaw called CVE-2024-55591 was used in real attacks before a fix was available (a so-called zero-day attack). This was a serious flaw that let attackers bypass authentication and seize the highest privileges on the device, and Fortinet formally disclosed it on January 14, 2025. Many FortiGate units were taken over during this period.
The problem came afterward. In April 2025, Fortinet disclosed a "persistence trick" planted by attackers. Those who succeeded in breaking in had placed a symbolic link (an OS mechanism that creates a "shortcut" to a file or folder) in the folder holding SSL-VPN language files. This shortcut connected to the device's internal files, so even after the owner changed passwords or updated firmware, the attacker could keep reading configuration files. Fortinet distributed patches and detection signatures to remove the trick and stop it from being recreated.
This "they stay even after the break-in" problem troubled administrators worldwide, and many devices in Japan are believed to have been affected. Network-edge devices being used in real attacks is a pattern shared with the recently reported hardcoded-password issue in Cisco's firewall management software. Equipment placed at the entrance to the internet continues to be a favorite target.
What is new about CVE-2025-68686
CVE-2025-68686 is a flaw that slips past the "persistence patch" from April 2025 described above. Fortinet's own advisory states plainly that "this vulnerability can only be abused as a consequence of a threat actor exploiting a known vulnerability to implement read-only access to vulnerable FortiGate devices, at the file system level."
Technically, the countermeasure added to block persistence was essentially a "password check" that matched whether the request path contained a specific string (the path for language files). According to analysis by security media, attackers found a way around this check and, by sending slightly reshaped HTTP requests, were able to read internal files again even on patched devices. Because the patch only rejected "one specific phrasing," the same thing could be done with a different phrasing.
To exploit this flaw, once again, an attacker must first reach a state where they can touch the device's files via a separate flaw. That is why the severity is "medium." But turned around, it means that any device suffering real harm from this flaw has already been broken into once. That is the significance of the KEV listing.
Is my device affected? (version quick reference)
The affected range and fixed versions shown in Fortinet's security advisory (FG-IR-25-934) are as follows. First, check your device's FortiOS version in the management console.
| FortiOS branch | Affected versions | Action |
|---|---|---|
| 7.6 | 7.6.0 through 7.6.1 | Update to 7.6.2 or above |
| 7.4 | 7.4.0 through 7.4.6 | Update to 7.4.7 or above |
| 7.2 | All versions | Migrate to a fixed branch |
| 7.0 | All versions | Migrate to a fixed branch |
| 6.4 | All versions | Migrate to a fixed branch |
Note that devices without the SSL-VPN feature enabled are not affected by this flaw. If you cannot raise the version immediately, Fortinet also offers a virtual patch (a temporary defense that blocks attacks without updating the device, delivered via FMWP database update 26.033). Still, the real fix is updating to a corrected version. If you do not use SSL-VPN, disabling it is itself an effective way to reduce risk.
What to check right now
As stated at the top, what truly matters here is not the version update but checking "whether you were breached in the past." A device where this flaw can be abused has, by definition, already been broken into once. The following are actions to take now, based on confirmed facts.
✓ Recommended actions based on confirmed facts
- ✓Update FortiOS to a fixed version (see the affected-versions table in FG-IR-25-934)
- ✓Inspect logs and configuration for signs of a break-in via CVE-2024-55591 or similar since November 2024 (use IoC information from vendors such as Tenable's scan details)
- ✓If a break-in is suspected, re-issue all passwords, certificates, and pre-shared keys for administrators and VPN users
- ✓Review whether the SSL-VPN management interface is exposed directly to the internet (CISA guidance)
- ✓Disable the SSL-VPN feature if you do not use it
In the U.S., federal agencies are required to respond by August 10, 2026. Ordinary companies in Japan have no legal deadline, but since active attacks have been confirmed, moving on the same timeline is the safe choice. We continuously track the bigger picture of actively exploited flaws in our roundup of the CISA KEV (the list of actively exploited vulnerabilities).
The timeline so far
← Swipe to move
The other flaw added the same day
CISA added one more flaw to the KEV on July 27 besides FortiOS: a flaw in the SD-WAN management software "VeloCloud Orchestrator" from Arista Networks (formerly VMware) (CVE-2026-16812). Unlike FortiOS, this one is in the most serious class (CVSS 10.0), allowing a device to be taken over from the outside without authentication, and it too has confirmed active attacks. It deserves attention because the management software that controls an entire company's network operations is being targeted.
Network devices like FortiGate, Cisco's firewall management software, and SD-WAN management software like VeloCloud — the products that act as the "checkpoints" of corporate networks — are being targeted one after another. Security Affairs also reported that both entered the KEV at the same time.
Summary
CVE-2025-68686, found in FortiOS, the base software of FortiGate, is rated only medium in severity, but it has been confirmed as a "tool for staying hidden after breaking in" in real attacks and is now listed in CISA's KEV. Because it is not a flaw that can be attacked from the outside on its own, a clean device will not be breached by this issue alone.
Even so, what administrators of FortiGate with SSL-VPN enabled should do is clear. First, update to a fixed version, and second, check for signs of a past break-in. If the device is in a state where this flaw applies, it has most likely already been taken over once. Do not be lulled by the low number, but do not panic either — take the time to verify the state of your own device.
References
- ▸ FortiGuard Labs - SSL-VPN Symlink Persistence Patch Bypass (FG-IR-25-934)
- ▸ NVD - CVE-2025-68686 Detail
- ▸ CISA - Adds Two Known Exploited Vulnerabilities to Catalog (July 27, 2026)
- ▸ CISA Known Exploited Vulnerabilities Catalog - CVE-2025-68686
- ▸ Cyber Security News - CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks
- ▸ Security Affairs - CISA adds Arista VeloCloud and Fortinet FortiOS flaws to KEV
- ▸ Tenable - CVE-2024-55591: Fortinet Authentication Bypass Zero-Day (background)
- ▸ Tenable - FortiOS SSL-VPN Symlink Persistence Patch Bypass scan details

Makoto Horikawa
Backend Engineer / AWS / Django