CISA KEV: FortiOS CVE-2025-68686 Security Update Checklist
July 28, 2026
CISA added FortiOS CVE-2025-68686 to its Known Exploited Vulnerabilities catalog on July 27, 2026. Fortinet describes the issue as an information-exposure risk in FortiOS SSL-VPN that can let an unauthenticated attacker bypass a patch intended to address a symbolic-link persistence mechanism in certain post-compromise situations.
This is not a reason to postpone normal incident-response work. Treat the KEV addition as an urgent prompt to apply Fortinet’s supported fixed release, review whether the SSL-VPN appliance was previously compromised, and keep administration tightly controlled while the change is completed.
Who should act now
- Inventory FortiOS appliances that provide SSL-VPN services, including appliances managed by a hosting, network, or security team.
- Confirm the exact installed FortiOS release against Fortinet PSIRT advisory FG-IR-25-934 and the release notes for the branch you run.
- Do not rely on an old remediation note alone. The advisory concerns a way a prior persistence fix could be bypassed after an earlier compromise.
Plan the supported update
- Assign an owner for the firewall, the remote-access service, monitoring, and emergency user communication.
- Review Fortinet’s fixed-version guidance for the active release train. Use a supported destination release and follow the vendor’s upgrade notes rather than applying an unverified workaround.
- Schedule an appropriate maintenance window and validate redundant or high-availability behavior according to the installed design.
- Keep a documented recovery plan available, but do not change unrelated VPN, identity, routing, DNS, or firewall policy during this security update.
Review for signs a previous compromise needs investigation
Because the vendor describes a post-compromise persistence concern, a successful package update alone may not close the operational question. Review approved administrator changes, remote-access configuration, account ownership, unexpected system changes, and security-monitoring history using your established incident-response process. Escalate suspicious findings through the responsible security team and Fortinet support.
Verify service safely after maintenance
- Confirm the appliance reports the intended FortiOS release.
- Validate an approved remote-access workflow, administrative access, logging, alert delivery, and the normal high-availability state when applicable.
- Confirm the firewall continues to protect legitimate customer, staff, monitoring, backup, and approved integration traffic.
- Record the version, maintenance window, validation owner, and any follow-up investigation in the change record.
Coordinate application checks after firewall maintenance
After the platform change, check representative public services and business workflows. Teams responsible for WordPress sites can use the Fix I.T. Phill WordPress Support hub and the WordPress security update checklist for the application-layer maintenance that remains separate from FortiOS remediation.

