Fortinet Product Security Update Advisory (CVE-2025-68686)

Fortinet Product Security Update Advisory (CVE-2025-68686)

Overview


Fortinet has released a security update addressing CVE-2025-68686, a vulnerability in FortiOS.

Vulnerability Details


This vulnerability is described as a symbolic link-based persistence block patch bypass vulnerability. A symbolic link is a method of linking a file or Path to another location, and a persistence block patch can be understood as a measure to prevent threat actors from attempting to maintain persistence or to maintain their configuration or access.

Affected Products


The following FortiOS versions are affected:

  • All versions of FortiOS 6.4.
  • All versions of FortiOS 7.0.
  • All versions of FortiOS 7.2.
  • FortiOS 7.4.0 Through 7.4.6.
  • FortiOS 7.6.0 Through 7.8.1.

Resolved Versions


Fortinet has provided patches through the latest updates.

  • FortiOS 7.4.7 And later.
  • FortiOS 7.6.2 And later.

Users of these products should update to the latest version that includes the Vulnerability Patch for this vulnerability, following the instructions on the reference site.

Reference


  • [1] SSL-VPN Symlink Persistence Patch Bypass. Https://fortiguard.Fortinet.Com/psirt/FG-IR-25-934