Fortinet FortiOS Persistence Bypass Added to CISA KEV
CISA added CVE-2025-68686 to KEV today — a FortiOS patch bypass that lets attackers restore persistence after an initial compromise. Affects 7.0 through 7.6.
CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog on July 27, 2026. The flaw is a bypass for the patch Fortinet shipped to address the symbolic link persistence technique — the one threat actors were abusing in 2025 to maintain read-only filesystem access across firmware updates and reboots.
CVSS is 5.9 (medium). That score reflects a real precondition: an attacker needs filesystem-level access to the FortiOS device first. What the score doesn’t reflect is the operational context. If a device was compromised during the 2025 SSL-VPN exploitation campaigns and the attacker applied this bypass before Fortinet’s mitigation landed, patching the original issue doesn’t close them out. CISA’s KEV addition confirms this is happening in the wild, not in theory.
Affected versions
Per NVD and Fortinet’s PSIRT advisory FG-IR-25-934: FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, and all versions of 7.2, 7.0, and 6.4.
What to do
Check your version first. For 7.6.x and 7.4.x, patched releases are listed in FG-IR-25-934 — consult the advisory directly for the specific fixed build numbers. For 7.2, 7.0, and 6.4: the entire branch is in scope, which means an upgrade rather than an in-branch patch.
If the device was Internet-facing during the 2025 wave, assume prior compromise. FortiOS SSL-VPN bugs from that period were mass-exploited at scale. An unpatched or late-patched device in that window should be treated as a forensics case, not just a patch-and-move-on. Run the triage outlined in CISA’s BOD 26-04 implementation guidance — checking configuration integrity, looking for unauthorized accounts, and reviewing filesystem state.
Federal agencies: BOD 26-04 puts you on a remediation deadline. The binding directive’s forensic requirements are in scope for KEV additions. The CISA guidance link above covers what that looks like in practice.
Context
Fortinet has had consistent KEV presence this year. Two unauthenticated RCEs in FortiSandbox hit the catalog earlier this month — CVSS 9.8 each. CVE-2025-68686 is lower severity in isolation, but that framing only holds if you’re starting from a clean device. For anything that was in the path of 2025 exploitation, it’s the mechanism keeping an attacker resident after you thought you’d evicted them.
The full CISA KEV list and our Fortinet vulnerability coverage have the broader picture.
- [ MEDIUM ] CVE-2025-68686 FortiOS patch bypass re-enables symbolic link persistence on compromised devices
Found this useful? Share it.

