Security · 1h ago
FortiOS CVE-2025-68686 Lets Attackers Bypass Symlink Fixes
CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog. The flaw allows attackers who already compromised a FortiOS device to bypass symlink persistence mitigations via crafted HTTP requests. Affected versions include FortiOS 6.4, 7.0, 7.2, 7.4.0–7.4.6, and 7.6.0–7.6.1.
Meridian48 take
The vulnerability underscores that patching alone isn't enough—organizations must also verify that no backdoors remain after an intrusion.
Read the full reporting
FortiOS CVE-2025-68686: Bypass of Symlink Persistence Mitigation for Already Compromised Devices →
DEV Community
fortioscve-2025-68686