🔴 Critical  |  Source: CISA Known Exploited Vulnerabilities


A vulnerability in Fortinet FortiOS allows remote unauthenticated attackers to bypass a previously issued patch designed to address a symbolic link persistence mechanism used in post-exploitation scenarios. An attacker must have already compromised the device at the filesystem level via a separate vulnerability to exploit this flaw. Its presence on the CISA KEV catalogue confirms active exploitation in the wild, making prompt remediation essential.

Security Architect’s Take: If FortiOS devices are part of your network perimeter or cloud connectivity stack, apply Fortinet’s latest patch immediately and audit for indicators of compromise at the filesystem level. Additionally, review SSL-VPN exposure and consider restricting management interfaces to trusted IP ranges to reduce the initial attack surface.

Original advisory: CVE-2025-68686: Fortinet FortiOS