FortiOS patch bypass re-enables symbolic link persistence on compromised devices
FortiOS 7.0–7.6 patch bypass restores symbolic link persistence on already-compromised devices via crafted HTTP requests. Added to CISA KEV July 2026.
- Vendor
- Fortinet
- Product
- FortiOS
- CVSS
- 5.9
- EPSS (exploit probability)
- N/A
- Status
- kev
- Published
CVE-2025-68686 covers a bypass of the patch Fortinet shipped for the symbolic link persistence mechanism observed in FortiOS post-exploitation. A remote unauthenticated attacker who has already compromised the target at the filesystem level — via another vulnerability — can send crafted HTTP requests to undo Fortinet’s own mitigation and restore that persistence channel. Source: Fortinet PSIRT advisory FG-IR-25-934 and NVD.
CISA added it to the Known Exploited Vulnerabilities catalog on July 27, 2026, confirming active exploitation in the wild.
Affected versions
FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, and all versions of 7.2, 7.0, and 6.4 per NVD.
What to do
Check your running FortiOS version against the patched releases listed in FG-IR-25-934. If you’re on 7.2, 7.0, or 6.4, those branches are entirely in the affected range — that means upgrading to a patched major release, not patching within-branch.
If there’s any chance the device was compromised via another FortiOS vulnerability before this fix was applied — the 2025 SSL-VPN exploitation wave is the obvious candidate — treat it as potentially persistently backdoored and run the forensic triage outlined in CISA’s BOD 26-04 implementation guidance. Federal agencies under BOD 26-04 have a mandatory remediation deadline tied to this KEV addition.
