CVE-2025-68686
FortiOS Post-Exploit Persistence Patch Bypass
Research Framing
| Field | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Track CVE-2025-68686 as an actively exploited FortiOS vulnerability: explain what the bypass does, why a 5.9 Medium score still deserves urgent action, which releases are affected or fixed, and what CISA KEV and CWE-200 add to the decision. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | What is confirmed: Fortinet says another vulnerability must first compromise FortiOS at filesystem level. An attacker can then send crafted HTTP requests, without authenticating for this bypass step, to defeat an earlier fix for symbolic-link persistence. [1][3][4] Why it matters: This is not the first break-in; it is a way to preserve attacker-relevant state after an owner believes remediation removed it. On a firewall and VPN control plane, that creates an integrity and trust problem, not merely a patch-status problem. Severity and urgency: The official score is CVSS 5.9 Medium because attack complexity is High. Confidentiality impact is High. CISA’s 27 July KEV addition separately confirms real-world exploitation and sets a 10 August federal action date. [1][2][3][4][5][6] What remains unanswered: The authoritative public record does not name the prerequisite vulnerability, actor, victim, victim count, exploited-device count, specific exposed information, or ransomware campaign. Those questions require new authoritative reporting or local incident evidence. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Decision Standard | The brief must let an owner answer five separate questions with evidence: Do we own an affected asset? Was it reachable while affected? Is it now on a documented fixed release? Is there evidence of prior attacker activity or persistent state? Can we prove the appliance, its HA/management paths, and the trust it could reach are safe to return to service? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Evidence Limits | Affected does not mean exposed; exposed does not mean exploited; suspicious does not mean attributed; patched does not mean clean. CWE-200 describes a broad confidentiality consequence and cannot identify the precise coding defect or complete exploit chain. CISA’s ransomware value is Unknown, which is an unconfirmed relationship—not evidence of absence. [2][7] |
CVE-2025-68686 Watch Snapshot
| Decision Field | Current Answer |
|---|---|
| Exploitation | CISA Known Exploited Vulnerability added 27 Jul 2026 [2] |
| CVSS severity | 5.9 Medium (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). The score reflects a difficult exploit precondition; it does not reduce the urgency of investigating an appliance that may already have been compromised. [1][3][4] |
| Weakness classification | Fortinet maps the CVE to CWE-200, exposure of sensitive information to an unauthorized actor. MITRE marks this broad category as discouraged for precise root-cause mapping. [1][3][7] |
| Required action date | 10 Aug 2026 for U.S. federal civilian agencies [2] |
| Critical precondition | The attacker must first have compromised FortiOS at filesystem level through another vulnerability [1][3][4] |
| Fixed releases listed | FortiOS 7.6.2+ and 7.4.7+ [1][4] |
| Known ransomware use | Unknown in CISA KEV; this means CISA has not identified that relationship in the catalog, not that ransomware is impossible [2] |
| Public victims / actor | None identified in the retained authoritative sources |
1-Topic
FortiOS is the operating system inside FortiGate security appliances—the equipment many organizations place at the edge of their networks to control firewall policy, VPN access, routing, administration, logging, and trusted connections. CVE-2025-68686 matters because it affects the trustworthiness of that control plane after a deeper compromise has already occurred. [1][3][4]
Fortinet says another vulnerability must first let the attacker compromise the FortiOS filesystem. The attacker can then send crafted HTTP requests, without authenticating for this later step, to bypass an earlier patch for a symbolic-link persistence mechanism. In ordinary language: this is not the first door into the appliance; it is a way to defeat an attempted cleanup and preserve attacker-relevant state.[1][3][4]
This CVE Watch Brief tracks authoritative changes to exploitation status, affected versions, fixed releases, severity, weakness classification, and response requirements. CISA added the CVE to KEV on 27 July 2026 and set a 10 August federal required-action date.[2][5][6]
The public record does not identify the earlier vulnerability, actor, victims, victim count, or ransomware outcome. The product therefore keeps four states separate: an affected product, an exposed asset, suspicious local evidence, and a confirmed incident.
2-Persona / Audience Lens
| Audience | Decision This Brief Supports | Evidence They Should Demand | Sources |
|---|---|---|---|
| Executives / business owners | Whether the organization has a material perimeter-trust issue and who owns the response. | Affected assets, historical reachability, business dependencies, findings, remediation, and return-to-service basis. | [1][2][6] |
| Network / FortiGate engineering | Which appliances and branches require restriction, upgrade, migration, HA scoping, or rebuild. | Serials, roles, versions, exposure, configurations, peers, managers, backups, and approved changes. | [1][4] |
| SOC / DFIR | Whether prior exposure became compromise and whether attacker-controlled state survived. | Filesystem, administration, authentication, configuration, network, time, HA, and upstream telemetry. | [1][2][6] |
| Identity / application owners | Which sessions, credentials, keys, certificates, tokens, and downstream systems require scoping. | Reachability and trust map tied to rotation and invalidation records. | [2][6] |
| MSPs / providers / insurers | Whether shared administration creates portfolio scope without assuming common compromise. | Customer-by-customer version, exposure, preservation, findings, trust actions, and closure evidence. | [2][6] |
| Legal / communications | What can be stated about exposure, compromise, victims, attribution, and ransomware. | Source-backed claim language and local incident facts separated by confidence. | [1][2][3][4] |
3-BLUF
- CISA added CVE-2025-68686 to KEV on 27 Jul 2026 and set a 10 Aug required-action date for federal civilian agencies. [2]
- In plain language, an attacker who already broke into the FortiGate deeply enough to change its filesystem may be able to defeat an earlier cleanup for a persistence method. That can leave the attacker relevant after the owner believes the device was fixed. [1][3][4]
- This CVE is not the initial break-in. It requires a separate, earlier vulnerability to provide filesystem-level compromise, and the public authoritative record does not identify that prerequisite CVE. [1][3][4]
- The CNA score is 5.9 Medium—not because the outcome is harmless, but because exploitation has a difficult prerequisite. The vector rates confidentiality impact High, with no separately rated integrity or availability impact. [1][3][4]
- Fortinet maps the weakness to CWE-200: sensitive information exposed to someone not authorized to receive it. MITRE warns that CWE-200 is a broad impact category, so it should not be presented as the exact software root cause. [1][3][7]
- An affected device that was internet-exposed before remediation needs forensic triage. Installing 7.6.2+ or 7.4.7+ closes the documented path but does not prove the appliance was clean. [1][2][4][6]
- FortiOS 7.2, 7.0, and 6.4 are listed as affected with no fixed release in those branches. Owners should migrate to a supported fixed branch or obtain explicit Fortinet guidance. [1][4]
- No retained authoritative source names an actor, victim, victim count, prerequisite CVE, or ransomware campaign. CISA’s ransomware field is Unknown. [2]
- Preserve logs and filesystem/configuration evidence before destructive cleanup; then scope credentials, secrets, and internal systems reachable through the appliance. [2][6]
4-Executive Summary
FortiGate appliances often sit at the boundary between an organization and the internet. They can terminate VPN connections, enforce network policy, route traffic, hold certificates and credentials, and expose an administrative control plane. A persistent attacker on that device may therefore have a better position than an attacker on an ordinary endpoint: the appliance can see trusted traffic and may connect directly to sensitive internal systems.
CVE-2025-68686 does not describe the original break-in. Fortinet says a separate vulnerability must first allow an attacker to compromise FortiOS at filesystem level. In some post-exploitation cases, attackers used symbolic links—a filesystem mechanism that points one file location to another—as part of persistence. This CVE allows crafted HTTP requests to bypass Fortinet’s earlier patch for that persistence mechanism. Put simply: the attacker must already be inside, but may be able to defeat the owner’s attempt to remove the foothold. [1][3][4]
The formal CVSS 3.1 score is 5.9 Medium. Its vector—AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N—says the attack is reachable over a network, needs no authenticated account or user click, but has high complexity because the filesystem must already be compromised. The rated impact is High for confidentiality and None for integrity and availability. That score describes the CVE in isolation. It should not be used to downgrade a real appliance investigation when the prerequisite itself means an attacker may already have achieved privileged access. [1][3][4]
Fortinet assigns CWE-200, “Exposure of Sensitive Information to an Unauthorized Actor.” In practical terms, the documented consequence is that information the attacker should not be able to obtain may remain exposed. MITRE labels CWE-200 a broad category and discourages using it as a precise root-cause mapping. The responsible reading is therefore: CWE-200 describes the confidentiality consequence in the vendor record; it does not tell us exactly which data was taken, name the underlying initial-access bug, or fully explain the symbolic-link patch bypass. [1][3][7]
On 27 July, CISA moved the CVE into the Known Exploited Vulnerabilities Catalog. That turns a theoretical product risk into a known-exploitation response problem and sets a 10 August required-action date for federal civilian agencies. CISA also points to forensic-triage requirements. For other organizations, the deadline is not automatically binding, but the underlying signal is still important: exploitation has been observed and an exposed affected device deserves a short, owned response window.[2][5][6]
Owners should identify every affected appliance, restrict exposed administration, preserve evidence, upgrade to 7.6.2+ or 7.4.7+, and investigate historical access. Older 7.2, 7.0, and 6.4 branches remain listed as affected without a fixed release in the CNA solution field; remaining on the newest build of one of those branches is not a documented fix.[1][4]
The practical closure question is not merely “Did the version number change?” Forensic triage should focus on unexpected symbolic links and filesystem changes, administrative and authentication activity, configuration drift, account and session changes, process or service changes, network egress, and evidence from both members of an HA pair. If integrity cannot be established, restore from trusted media and a validated configuration rather than declaring the incident closed because the version number changed. [2][6]
The public record remains narrow. It does not identify the prerequisite vulnerability, actor, victim, victim count, or ransomware outcome. CISA’s Unknown ransomware field is an unconfirmed relationship, not reassurance. Executive reporting should say “known exploitation of a post-compromise persistence bypass” and keep local exposure, compromise, attribution, and business impact separate. [2]
5-Why It Matters
6-Vulnerability Details
| Field | Official Record | Plain Meaning |
|---|---|---|
| Product | FortiOS | The operating system used by FortiGate network-security appliances. |
| Vulnerability class | Patch bypass for symbolic-link persistence observed after exploitation | An attacker may be able to defeat an earlier attempt to remove a foothold from the appliance. |
| Attacker position | Remote and unauthenticated for this bypass | The bypass request itself does not need a valid FortiOS account or a user click. |
| Required precondition | Another vulnerability must first produce filesystem-level compromise | This CVE is useful only after a separate break-in has already given the attacker deep control of the device. |
| Documented consequence | Exposure of sensitive information to an unauthorized actor | Information protected by the appliance may remain visible to someone who should not have it; the exact information requires local investigation. |
| Official classification | CVSS 5.9 Medium; CWE-200; CISA KEV [1][2][3][4][7] | Moderate isolated CVSS score, broad confidentiality category, and confirmed real-world exploitation. |
7-Affected Products & Fixed Versions
| Branch | Affected | Documented Action | Sources |
|---|---|---|---|
| FortiOS 7.6 | 7.6.0–7.6.1 | Upgrade to 7.6.2 or later | [1][3][4] |
| FortiOS 7.4 | 7.4.0–7.4.6 | Upgrade to 7.4.7 or later | [1][3][4] |
| FortiOS 7.2 | 7.2.0–7.2.13 (all versions in the CNA record) | No fixed 7.2 release is listed; move to a vendor-supported fixed branch or obtain Fortinet direction | [1][4] |
| FortiOS 7.0 | 7.0.0–7.0.19 (all versions in the CNA record) | No fixed 7.0 release is listed; move to a vendor-supported fixed branch or obtain Fortinet direction | [1][4] |
| FortiOS 6.4 | 6.4.0–6.4.16 (all versions in the CNA record) | No fixed 6.4 release is listed; move to a vendor-supported fixed branch or obtain Fortinet direction | [1][4] |
8-Severity and Operational Priority
| Dimension | Authoritative Answer | What It Means for the Owner |
|---|---|---|
| Base score | CVSS 3.1 5.9 · Medium [1][3][4] | The numerical rating is not Critical. Report it accurately; do not replace it with an invented score. |
| Attack path | Network reachable; no privileges or user interaction; high attack complexity | The attacker does not need a valid FortiOS account or a user click, but must first obtain filesystem-level compromise through another vulnerability. |
| Rated impact | Confidentiality High; integrity None; availability None | The formal record emphasizes unauthorized information exposure. Local evidence—not the vector alone—must determine whether configuration, credentials, traffic, or downstream systems were affected. |
| Operational priority | Known exploitation in CISA KEV; federal action due 10 Aug 2026 [2][5][6] | Treat an affected appliance with historical internet exposure as an urgent remediation-and-forensics case. A Medium score does not cancel the fact that exploitation is known or that the prerequisite implies an earlier compromise. |
9-CWE Weakness Classification
| Field | Answer | Important Boundary |
|---|---|---|
| Vendor / CNA mapping | CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor [1][3][7] | This is the category carried by the official CVE record. |
| Plain-language meaning | The product can reveal information to someone who is not allowed to receive it. | The authoritative sources do not enumerate the exact information exposed in every affected environment. |
| Mapping precision | MITRE marks CWE-200 as DISCOURAGED for precise vulnerability mapping because it is broad and often describes impact rather than root cause. [7] | Do not present CWE-200 as proof that a particular coding error created the symbolic-link bypass. |
| How IntelliOS uses it | Retain CWE-200 for discovery, grouping, and confidentiality-impact analysis; pair it with the CVE narrative, CVSS vector, affected versions, KEV status, and vendor remediation. | CWE similarity does not establish shared exploitability, active exploitation, actor, campaign, or business impact. |
10-KEV and Exploitation Status
| Field | Assessment |
|---|---|
| Known exploitation | Confirmed by CISA KEV; added 27 Jul 2026. [2] |
| Federal due date | 10 Aug 2026. [2] |
| Ransomware relationship | Unknown in the KEV catalog; no relationship is confirmed by the retained sources. [2] |
| Public exploit / reproduction | Not used in this defensive brief. The authoritative records are sufficient for action and do not require publishing exploit-enablement detail. |
| Severity | Fortinet/CNA rates the issue Medium. Operational priority is higher for previously exposed devices because exploitation presupposes an earlier filesystem compromise. [1][3][4] |
11-Technical Preconditions and Attack Flow
| Step | What Is Known | Why It Matters | What Is Not Established |
|---|---|---|---|
| 1 · Separate initial compromise | Another vulnerability must first compromise FortiOS at filesystem level. | The device may already have suffered a deeper compromise before CVE-2025-68686 becomes usable. | The public authoritative record does not identify the prerequisite CVE, actor, date, or initial-access method. |
| 2 · Persistence mechanism | Symbolic-link persistence was observed in some post-exploitation cases. | Persistence is designed to preserve attacker access or state after the owner attempts remediation. | The sources do not provide a universal indicator set or prevalence estimate. |
| 3 · Patch bypass | A remote unauthenticated attacker can use crafted HTTP requests to bypass the prior fix. | A device may appear remediated while attacker-relevant filesystem state remains. | The CVE is not described as a standalone initial-entry exploit. |
| 4 · Documented consequence | Sensitive information may be exposed to an unauthorized actor. | A FortiGate may hold or observe configuration, identity, certificate, VPN, and traffic information important to further compromise. | The sources do not say which data was accessed in a specific organization; local evidence must answer that. |
12-Observables and Evidence
| Evidence Source | Preserve / Compare | Question It Answers |
|---|---|---|
| Filesystem and firmware | Filesystem metadata, unexpected links, changed files, package/firmware state, integrity or baseline output | Did untrusted persistence or modification survive remediation? |
| Administrative identity | Admin logins, failed attempts, source addresses, new/changed accounts, API access, active sessions | Who controlled the appliance and when? |
| Configuration and HA | Configuration revisions, policy/routing/VPN changes, HA synchronization and peer state | What trust or traffic path changed, and did state propagate? |
| Network telemetry | Inbound management traffic, unusual HTTP requests, outbound connections, internal destinations reached from the appliance | Was the device contacted or used as a pivot? |
| Reachable credentials and secrets | Credential inventory, certificates, API tokens, directory binds, shared secrets and rotation history | Which downstream trust must be invalidated? |
| Time and retention | Clock state, timezone, log rollover, upstream copies, SIEM and provider retention | Can the team construct a reliable exposure and activity window? |
13-Detection and Hunting
- Compare current and known-good filesystem metadata and configuration; investigate unexpected symbolic links, modified files, accounts, policies, routes, VPN settings, scripts, and automation.
- Review administrative and authentication activity from before the public KEV addition through remediation, including successful and failed access, API use, session creation, and activity from unfamiliar networks.
- Examine inbound management-plane HTTP activity and outbound or internal connections originating from the appliance; correlate with firewall, proxy, DNS, EDR, identity, and downstream-system logs.
- Scope both HA members, backups, centralized managers, and any MSP tooling. A clean primary node does not prove the peer or a restored configuration is trustworthy.
- Treat missing logs as a scoping limitation. Do not convert insufficient retention into a conclusion that exploitation did not occur.
14-Incident Response Playbook
| Time | Owner | Action | Closure Evidence | Sources |
|---|---|---|---|---|
| 0–2 hours | Network / asset owner | Identify every FortiOS instance, exact branch and build, HA peer, public management or VPN exposure, external administrator, and business service dependency. Restrict exposed administration paths while preserving access for response. | Asset list, version output, exposure evidence, owner, change ticket | [1][2][4][6] |
| 0–4 hours | Incident response | Preserve configuration, audit and authentication logs, system-event logs, traffic records, filesystem metadata, administrative-session history, HA state, and available upstream network telemetry before cleanup or rebuild. | Time-bounded evidence package with hashes and collection notes | [2][6] |
| 0–8 hours | FortiGate engineering | Upgrade 7.6 to 7.6.2+ or 7.4 to 7.4.7+. Do not leave 7.2, 7.0, or 6.4 on an affected branch merely because it is the newest build in that branch; obtain a supported migration path from Fortinet. | Pre/post version evidence, approved change, health checks | [1][4] |
| Same day | SOC / DFIR | Review for unexpected symbolic links, unusual filesystem changes, administrative access, configuration changes, new accounts, suspicious HTTP activity, process or service changes, and outbound connections. Compare both HA members and known-good baselines. | Hunt queries, results, exceptions, analyst disposition | [1][2][6] |
| Same day–48 hours | Identity / network / application owners | If prior compromise is plausible, invalidate administrative sessions and rotate credentials, API tokens, certificates, shared secrets, directory-service bind accounts, and other secrets the appliance could access. Scope internal systems reached from the appliance. | Credential and session closure record tied to reachable blast radius | [1][2][6] |
| 24–72 hours | Incident commander | If integrity cannot be established, rebuild from trusted media and validated configuration rather than treating an in-place upgrade as incident closure. Test policy, routing, VPN, HA, logging, and monitoring before return to service. | Known-good recovery record and signed return-to-service decision | [2][6] |
15-Decision-Ready Actions
- Name a technical owner and business owner for every matched FortiOS asset.
- Block or tightly restrict public administration; confirm whether VPN, partner, cloud, or MSP paths still provide reachability.
- Preserve evidence before factory reset, reimage, or destructive cleanup.
- Move to a documented fixed release; do not treat an affected older branch as remediated.
- Escalate to incident response when prior exposure, missing evidence, suspicious state, or unknown integrity prevents a defensible clean finding.
- Rotate trust according to what the appliance could reach, not according to the CVSS number.
- Return to service only after version, configuration, identity, logging, HA, and network-path validation.
16-SMB, MSP, and Insurance Lens
Smaller organizations may not directly administer the FortiGate or retain its logs. Ask the MSP or provider for the device identifier, exact version history, exposure window, patch timestamp, evidence-preservation status, suspicious findings, credential/session actions, HA and backup scope, and return-to-service basis. Insurers and counsel should distinguish an affected product, an exposed asset, suspicious evidence, and a confirmed incident; those are not interchangeable facts.
17-Timeline of Notable Activity
| Date | Event | Why It Matters | Sources |
|---|---|---|---|
| 10 Feb 2026 | Fortinet publishes the CVE record | The CNA describes a remote unauthenticated patch bypass, but only after an attacker has already obtained filesystem-level compromise through another vulnerability. | [1][4] |
| 17 Jun 2026 | The public record is enriched | CISA ADP and CNA metadata updates sharpen affected-version and assessment context; this still does not name an actor, victim, or initial-access vulnerability. | [3][4] |
| 27 Jul 2026 | CISA adds CVE-2025-68686 to KEV | The decision changes from ordinary vulnerability management to known-exploitation response. CISA also requires Forensics Triage Requirements and an internet-exposure assessment. | [2][5][6] |
| 28 Jul 2026 | Canonical records and IntelliOS products are reconciled | The current Fortinet CNA record lists 7.6.2+ and 7.4.7+ as fixed; older listed branches remain affected and require migration or direct vendor guidance. | [1][3][4] |
| 10 Aug 2026 | CISA required-action date | The date applies to U.S. Federal Civilian Executive Branch agencies. Other organizations can use it as a defensible urgency benchmark, not as a substitute for their own exposure and incident decisions. | [2][5][6] |
18-Public Victim and Attribution Matrix
| Question | Retained Answer | How To Use It |
|---|---|---|
| Named public victim? | None in the retained authoritative sources. | Do not create a victim list from exposure scans or product ownership. |
| Victim or exploited-device count? | None published in the retained authoritative sources. | Do not infer prevalence from KEV membership. |
| Named actor or campaign? | None in the retained authoritative sources. | Do not import FortiBleed or another Fortinet actor story without direct evidence. |
| Prerequisite initial-access CVE? | Not specified. | Investigate the full historical attack surface instead of assuming one entry path. |
| Known ransomware use? | CISA KEV: Unknown. [2] | Keep ransomware unconfirmed; maintain ransomware-ready recovery because perimeter compromise can still enable it. |
19-Common Questions
| Question | Answer |
|---|---|
| Is this a critical remote takeover? | No. Fortinet/CNA rates it Medium and requires prior filesystem-level compromise. Its operational urgency comes from confirmed exploitation and the possibility of persistent attacker state on a perimeter control plane. |
| Why act urgently if the score is only 5.9 Medium? | CVSS rates this CVE in isolation and accounts for its high-complexity prerequisite. CISA KEV says exploitation is known, while the prerequisite means a potentially affected device may already have suffered filesystem compromise. Urgency comes from that combined condition, not from relabeling the score. |
| What does CWE-200 tell us? | It says the vendor classified the consequence as sensitive information exposed to an unauthorized actor. MITRE warns that CWE-200 is broad and discouraged for precise root-cause mapping, so it does not identify the exact coding defect, stolen data, actor, or exploit chain. |
| If we patch, are we done? | Not when the device was previously exposed or integrity is uncertain. Patch, preserve, investigate, scope reachable trust, and rebuild if clean state cannot be established. |
| Can we remain on FortiOS 7.2, 7.0, or 6.4? | Those listed branches are affected and the CNA solution lists only 7.6.2+ and 7.4.7+. Obtain a supported migration path from Fortinet. |
| Is this FortiBleed? | The retained official sources do not make that connection. Keep this CVE separate unless local or new authoritative evidence links them. |
| Does August 10 legally bind every company? | No. It is CISA's federal civilian required-action date. Non-federal organizations can use it as an urgency benchmark. |
20-Source Weighting and Contribution
| Source | Type | Contribution | Use |
|---|---|---|---|
| Fortinet PSIRT — FG-IR-25-934 — FortiOS symbolic-link persistence patch bypass | Vendor advisory | Controls the affected FortiOS branches, fixed releases, prerequisite compromise condition, CWE, and vendor severity. | Very High · controlling |
| CISA — Known Exploited Vulnerabilities Catalog — CVE-2025-68686 | Government KEV record | Controls known-exploitation status, the 10 Aug 2026 federal due date, required action, and the catalog's Unknown ransomware-use value. | Very High · controlling |
| NIST — National Vulnerability Database — CVE-2025-68686 | Government vulnerability record | Corroborates the CNA description, affected configurations, vendor reference, CWE-200, and CISA KEV status. | High · canonical corroboration |
| CVE Program / Fortinet CNA — CVE-2025-68686 canonical record | Canonical CVE record | Controls the current CNA wording, version ranges, available fixed releases, and current machine-readable metric. | Very High · controlling |
| CISA — BOD 26-04 — Prioritizing Security Updates Based on Risk | Binding operational directive | Provides the federal risk-prioritization framework referenced by the KEV required action. | High · operational context |
| CISA — BOD 26-04 implementation guidance and Forensics Triage Requirements | Government implementation guidance | Explains internet-exposure treatment and why KEV additions require forensic triage rather than patch-status reporting alone. | High · operational context |
| MITRE — CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor | Weakness taxonomy | Defines the vendor-assigned weakness category and supplies MITRE's warning that CWE-200 is broad and discouraged for precise root-cause mapping. | High · framework context |
| MITRE ATT&CK — Enterprise tactics | Threat-behavior framework | Defines the ATT&CK tactic names used to organize the source-supported post-compromise behavior without claiming unsupported technique-level attribution. | High · framework context |
21-Connected IntelliOS Products
CVE-2025-68686 CARDS Record
Canonical searchable CVE/KEV record.
FortiOS Persistence Bypass Flash Threat Brief
Incident response, forensic collection, containment, and recovery.
Government Cybersecurity Actions & Advisories
Government notices, deadlines, and decision priorities.
Exploitable Technology Risk
Cross-product view of technologies under active exploitation.
FortiBleed Fortinet Credential Exposure
Separate Fortinet credential-exposure intelligence; do not conflate the two records.
22-Notes
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
23-Citations
| # | Source | Date | Source Type | Contribution |
|---|---|---|---|---|
| 1 | Fortinet PSIRT — FG-IR-25-934 — FortiOS symbolic-link persistence patch bypass | 10 Feb 2026; current record checked 28 Jul 2026 | Vendor advisory | Controls the affected FortiOS branches, fixed releases, prerequisite compromise condition, CWE, and vendor severity. |
| 2 | CISA — Known Exploited Vulnerabilities Catalog — CVE-2025-68686 | 27 Jul 2026 | Government KEV record | Controls known-exploitation status, the 10 Aug 2026 federal due date, required action, and the catalog's Unknown ransomware-use value. |
| 3 | NIST — National Vulnerability Database — CVE-2025-68686 | Updated 27 Jul 2026 | Government vulnerability record | Corroborates the CNA description, affected configurations, vendor reference, CWE-200, and CISA KEV status. |
| 4 | CVE Program / Fortinet CNA — CVE-2025-68686 canonical record | Published 10 Feb 2026; updated 28 Jul 2026 | Canonical CVE record | Controls the current CNA wording, version ranges, available fixed releases, and current machine-readable metric. |
| 5 | CISA — BOD 26-04 — Prioritizing Security Updates Based on Risk | 2026 | Binding operational directive | Provides the federal risk-prioritization framework referenced by the KEV required action. |
| 6 | CISA — BOD 26-04 implementation guidance and Forensics Triage Requirements | 2026 | Government implementation guidance | Explains internet-exposure treatment and why KEV additions require forensic triage rather than patch-status reporting alone. |
| 7 | MITRE — CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor | Current definition checked 28 Jul 2026 | Weakness taxonomy | Defines the vendor-assigned weakness category and supplies MITRE's warning that CWE-200 is broad and discouraged for precise root-cause mapping. |
| 8 | MITRE ATT&CK — Enterprise tactics | Current framework checked 28 Jul 2026 | Threat-behavior framework | Defines the ATT&CK tactic names used to organize the source-supported post-compromise behavior without claiming unsupported technique-level attribution. |
24-Version Change Log
| Version | Date | Change | Monitoring |
|---|---|---|---|
| v2 | 28 Jul 2026 | Rebuilt Research Framing to the CVE Watch standard with interpreted questions, initial observations, tiered source coverage, and explicit evidence limits. Added a plain-language explanation, CVSS 5.9 vector and severity-versus-urgency analysis, CWE-200 definition and MITRE mapping caution, a four-step attack sequence, expanded BLUF and Executive Summary, and CWE-aware discovery guidance. | Daily KEV, NVD/CVE, CWE, vendor, and material-change check at 1:00 PM ET. |
| v1 | 28 Jul 2026 | Initial CVE Watch Brief publication following CISA's CVE-2025-68686 KEV addition. Added affected branches, fixed-release boundary, technical precondition, response playbook, forensic collection, timeline, attribution/victim matrix, connected products, and source contribution table. | Daily material-change check at 1:00 PM ET for six months; no-change runs do not publish or email. |
