CISA has added the actively exploited Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active attacks. The vulnerability affects Fortinet FortiOS, the operating system used across FortiGate firewalls and other Fortinet security products. It is classified as an exposure of sensitive information to an unauthorized actor issue, mapped to CWE-200. According to CISA, the flaw could allow a remote, unauthenticated attacker to bypass a patch designed to prevent a symbolic link persistence technique. Attackers can exploit the issue by sending specially crafted HTTP requests to a vulnerable device. However, successful exploitation has an important condition. The...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!