<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>VeloCloud Orchestrator On-Prem - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/velocloud-orchestrator-on-prem/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 27 Jul 2026 17:24:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/velocloud-orchestrator-on-prem/feed.xml" rel="self" type="application/rss+xml"/><item><title>Fortinet FortiOS CVE-2025-68686 Sensitive Information Exposure Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-07-fortinet-fortios-cve-2025-68686/</link><pubDate>Mon, 27 Jul 2026 17:24:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-fortinet-fortios-cve-2025-68686/</guid><description>A remote unauthenticated attacker can exploit CVE-2025-68686 in Fortinet FortiOS to bypass a previously applied patch, allowing sensitive information exposure and enabling persistence post-exploitation, provided the product was already compromised at the filesystem level via another vulnerability.</description><content:encoded><![CDATA[<p>CVE-2025-68686 describes a sensitive information exposure vulnerability in Fortinet FortiOS that has been added to CISA's Known Exploited Vulnerabilities Catalog. This vulnerability allows a remote unauthenticated attacker to bypass a previously deployed patch designed to mitigate symbolic link persistency mechanisms in post-exploitation scenarios. Exploitation requires that the attacker has already compromised the FortiOS product at the filesystem level through a separate, unspecified vulnerability. By sending specially crafted HTTP requests, attackers can circumvent the existing patch, re-establish persistence, and potentially access sensitive information. This vulnerability is critical for organizations using FortiOS, as it enables adversaries to maintain a foothold and continue malicious activities even after initial attempts to remediate persistence have been made.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker gains initial access to the Fortinet FortiOS product through an unspecified vulnerability, achieving filesystem-level compromise.</li>
<li>The attacker establishes persistence using symbolic link mechanisms, which are later patched by the vendor.</li>
<li>Despite the patch being applied, the attacker leverages their existing filesystem access.</li>
<li>The attacker crafts and sends malicious HTTP requests specifically designed to target the bypass vulnerability.</li>
<li>The crafted HTTP requests exploit CVE-2025-68686, bypassing the patch intended to prevent symbolic link persistency.</li>
<li>The symbolic link persistency mechanism is re-enabled or maintained, allowing the attacker to regain or sustain their persistent access.</li>
<li>Through this persistence, the attacker can then access and potentially exfiltrate sensitive information from the compromised FortiOS device.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2025-68686 allows an attacker to bypass critical security patches, re-establish persistence, and expose sensitive information within compromised FortiOS environments. While this vulnerability requires prior filesystem-level compromise, its inclusion in CISA's KEV catalog signifies that it is either actively exploited or poses significant risk to federal agencies, implying a broader risk to all organizations utilizing affected FortiOS products. The impact includes continued unauthorized access, data breaches involving sensitive network configurations or user data, and potential for further network pivot from the FortiGate device.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2025-68686 on all Fortinet FortiOS installations in accordance with vendor instructions provided in the FortiGuard PSIRT advisory FG-IR-25-934.</li>
<li>Review existing CISA BOD 26-04 guidance to ensure prioritization and adherence to patching deadlines for CVE-2025-68686, particularly for internet-exposed assets.</li>
<li>Implement CISA's Forensics Triage Requirements to ensure adequate logging and investigative capabilities are in place, particularly on systems where CVE-2025-68686 might have been exploited.</li>
<li>If unable to apply mitigations for CVE-2025-68686, consider discontinuing use of the affected FortiOS products or isolating them from critical networks.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>fortinet</category><category>fortios</category><category>vulnerability</category><category>cve</category><category>exposure</category><category>persistence</category></item></channel></rss>