Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Fortinet FortiOS
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N N U H N N 5.9 .0126 67.4 YES
AFFECTED
Product Versions Fixed
FortiOS 7.6.0 – —
TIMELINE
Dec 23 Reserved by fortinet
Jul 27 Added to CISA KEV, remediation due 2026-08-10
Jul 27 Published (CNA: fortinet)
Jul 28 RESCORED — CVE-2025-68686 (Fortinet FortiOS). CVSS 5.3 → 5.9 (NVD).
Aug 11 DUE DATE PASSED — CVE-2025-68686 (Fortinet FortiOS). CISA remediation deadline was August 10, 2026; still in catalog.
Description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| December 23, 2025 | Reserved | Reserved by fortinet |
| July 27, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-08-10 |
| July 27, 2026 | Published | Published (CNA: fortinet) |
| July 28, 2026 | RESCORED | RESCORED — CVE-2025-68686 (Fortinet FortiOS). CVSS 5.3 → 5.9 (NVD). |
| August 11, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2025-68686 (Fortinet FortiOS). CISA remediation deadline was August 10, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Fortinet | FortiOS | — | 7.6.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-68686 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.