CVE-2025-68686

Fortinet · FortiOS

A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.

Executive summary

This critical vulnerability in Fortinet FortiOS is currently being exploited in the wild and poses a significant risk of unauthorized information disclosure.

Vulnerability

This is an information disclosure vulnerability (CWE-200) where an unauthenticated remote attacker can leverage the flaw to access sensitive system information. The vulnerability does not require user interaction or high privileges to execute.

Business impact

The exposure of sensitive configuration or system information can serve as a precursor to more complex attacks, including network mapping or credential theft. With a CVSS score of 9.5 and confirmed active exploitation in the wild, this vulnerability represents an urgent threat to organizational security and data confidentiality.

Remediation

Immediate Action: Upgrade FortiOS to version 7.6.2 or 7.4.7 or above immediately to remediate the underlying flaw.

Proactive Monitoring: Review system logs for unusual access patterns or unauthorized attempts to query administrative endpoints.

Compensating Controls: Ensure that management interfaces are not exposed to the public internet and restrict access to these interfaces via trusted IP ranges only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the confirmed active exploitation and the critical nature of this disclosure, administrators must prioritize the deployment of the vendor patches. Failure to secure these devices exposes the organization to immediate compromise by threat actors currently targeting this specific vulnerability.