CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Summary
A critical vulnerability, CVE-2025-68686, has been identified in Fortinet FortiOS, allowing remote unauthenticated attackers to bypass existing patches and potentially access sensitive information. Attackers would first need to compromise the system at the filesystem level through another vulnerability to exploit this flaw.
IFF Assessment
This vulnerability allows an attacker to bypass patches and expose sensitive information, representing a significant risk to defenders.
Severity
The CVSS score is estimated based on the description of the vulnerability which allows for unauthorized access to sensitive information and bypass of existing patches via crafted HTTP requests, indicating a high impact and exploitability.
CISA KEV: Listed as actively exploited. Federal patch due: August 10, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability highlights the importance of timely patching and vigilance against sophisticated attack chains. Defenders should prioritize applying Fortinet's recommended mitigations and stay aware of any new exploits that chain this vulnerability with other filesystem-level compromises.