Fortinet FortiOS vulnerability added to CISA exploited list

CISA added CVE-2025-68686, a medium-severity vulnerability in Fortinet FortiOS that exposes sensitive information, to its Known Exploited Vulnerabilities catalogue. The flaw allows remote unauthenticated attackers to bypass security measures.

5 reportsother · primary

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2025-68686: Fortinet FortiOS — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

json:cisa-kevprimary64d ago kagi ↗

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. A

CISA has added a vulnerability to the KEV catalogue. - CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability https://www. cve.org/CVERecord?id=CVE-2

mastodon:infosec-exchangeother64d ago kagi ↗

CISA has added a vulnerability to the KEV catalogue. - CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability https://www. cve.org/CVERecord?id=CVE-2025- 68686 Also: Cisco tagged Apple yesterday for zero-day reports https:// talosintelligence.com/vulnerab ility_reports#zerodays @ TalosSecurity # Fortinet # CISA # infosec # vulnerability # Apple #

(CISA TS-SOC) CVE-2025-68686 – Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability Severity: MEDIUM Impact Summary: Exposure of sensitive information to unauthori

mastodon:infosec-exchangeother63d ago kagi ↗

(CISA TS-SOC) CVE-2025-68686 – Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability Severity: MEDIUM Impact Summary: Exposure of sensitive information to unauthorized actors due to patch bypass, potentially leaking data after prior compromise.... https:// thecybermind.co/2026/07/27/cis a-ts-soc-cve-2025-68686-fortinet-fortios-exposure-of-sensitive-information-t

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now. # CISA # KEV # Arista # VeloCloud # Fortinet # Forti

mastodon:infosec-exchangeother63d ago kagi ↗

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now. # CISA # KEV # Arista # VeloCloud # Fortinet # FortiOS # CVE # ExploitedInTheWild # Cybersecurity https:// securityonline.info/cisa-kev-a rista-velocloud-fortios/?utm_source=mastodon&utm_medium=jetpack_social

🚨 [CISA-2026:0729] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0729 ) CISA has added one new vulnerability to its Known Ex

mastodon:infosec-exchangeother61d ago kagi ↗

🚨 [CISA-2026:0729] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0729 ) CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder