CVE-2025-68686: Fortinet FortiOS
EPSS29.4%No. 1015 of 1739 in KEV
CVE year2025~1 yrs before listing
Same vendor in KEV31
Same product9
| Field | Value |
|---|---|
| Vendor | Fortinet |
| Product | FortiOS |
| Name | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability |
| Added to KEV | 2026-07-27 |
| US federal due date | 2026-08-10 |
| Ransomware use | Unknown |
| CWE | CWE-200 |
CISA description
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2019-6693 | Fortinet FortiOS | 2025-06-25 | 5.8% | Known |
| CVE-2024-21762 | Fortinet FortiOS | 2024-02-09 | 83.4% | Known |
| CVE-2022-41328 | Fortinet FortiOS | 2023-03-14 | 10.6% | Unknown |
| CVE-2022-42475 | Fortinet FortiOS | 2022-12-13 | 99.4% | Known |
| CVE-2021-44168 | Fortinet FortiOS | 2021-12-10 | 0.8% | Unknown |
| CVE-2020-12812 | Fortinet FortiOS | 2021-11-03 | 45.3% | Known |
| CVE-2019-5591 | Fortinet FortiOS | 2021-11-03 | 18.5% | Known |
| CVE-2018-13379 | Fortinet FortiOS | 2021-11-03 | 99.9% | Known |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Fortinet FortiOS vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-27.