Fortinet SSL-VPN Patch Bypass: What You Need to Do

CISA’s Known Exploited Vulnerabilities catalogue, the official US government list of flaws being actively targeted by attackers, was updated at the end of July to include CVE-2025-68686, a vulnerability in Fortinet’s FortiOS software that powers FortiGate firewalls. If your business runs a Fortinet firewall (and many businesses across Gloucestershire and the UK do), this one is worth understanding before your next routine check.

A bit of background

To make sense of CVE-2025-68686, it helps to know what came before it. Between 2022 and 2024, a series of serious flaws in FortiOS’s SSL-VPN feature (CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762) were actively exploited by criminal and state-sponsored attackers. Those vulnerabilities let attackers get into the firewall itself, not just through it, and they used that access to plant a persistent “symbolic link” (essentially a hidden shortcut in the device’s file system) that gave them ongoing access to sensitive configuration files, even after firmware updates were applied.

Fortinet patched this. The fix was designed to detect and remove those malicious shortcuts. Many businesses updated their firewalls and moved on, reasonably assuming the problem was resolved.

CVE-2025-68686 is a bypass for that fix. By adjusting a URL request with an extra forward slash, a trivially simple change, an attacker who had previously gained filesystem access on a Fortinet device can skip the protection check entirely and maintain a hidden foothold. CISA confirmed in late July 2026 that this technique is being exploited in the wild.

Why this matters even if you patched

This vulnerability does not give attackers a way into your firewall from scratch, it requires that the device was already compromised via one of the older flaws. That sounds reassuring at first, but the reality is more nuanced. If your Fortinet was running a vulnerable FortiOS version at any point during 2022-2024, and the device was not being closely monitored or formally investigated at the time, there is a real possibility that attackers gained a foothold before you applied the original patches.

For many organisations the reassurance was simple: “we patched, so we’re fine.” CVE-2025-68686 shows that patching addressed the entry point but may not have removed an attacker who was already in. They anticipated the fix and quietly bypassed it.

Which versions are affected

The affected FortiOS releases are:

  • FortiOS 7.6 – all versions before 7.6.2
  • FortiOS 7.4 – all versions before 7.4.7
  • FortiOS 7.2, 7.0, and 6.4 – all versions (migration to a fixed branch required)

The fixed releases are FortiOS 7.6.2 or later and FortiOS 7.4.7 or later. Devices on the 7.2, 7.0, or 6.4 branches cannot resolve this by upgrading within those branches, they need to move to a supported, fixed release.

What to check and do now

1. Confirm your FortiOS version. Log into your FortiGate management interface and check that you are running FortiOS 7.6.2 or later, or 7.4.7 or later. If not, schedule an upgrade as a priority.

2. Do not stop at the version number. If your device ran a vulnerable version and could have been exposed through the earlier SSL-VPN flaws, a version upgrade alone is not sufficient. Fortinet published specific guidance for checking whether a device has the malicious symlink installed, your IT team or support provider should work through this. Patching closes the door; it does not automatically remove someone who was already inside.

3. Review your VPN access logs. Look for unexpected authentication events, unfamiliar source IP addresses, or access patterns that do not match normal usage, particularly from the 2022-2024 period when the original vulnerabilities were being exploited.

4. Consider a formal review if you are unsure. If you have not had your Fortinet devices audited by a security professional, and they ran through any of the affected version ranges, a proper health check is worth doing.

What System Force IT has done

As part of our managed IT services, we take responsibility for keeping our clients’ Fortinet firewalls on current, supported firmware. Where clients are running affected versions, we are already reviewing and scheduling upgrades. We also carry out configuration audits as part of our ongoing work, so we are not relying purely on version numbers to assess device health.

If you have a Fortinet firewall managed in-house or by a previous provider and you are not certain of its current patch status, that uncertainty is itself a reason to act. Our IT security services include firewall management, device audits, and ongoing monitoring, and we can carry out a targeted review of your Fortinet devices to confirm their current state.

A vulnerability like this is also a useful reminder of why patching, while essential, is only one part of good security practice. Understanding whether a device has ever been compromised, and responding properly if it has, requires visibility and expertise that goes beyond applying a firmware update. If you would like guidance on how to approach that, our IT consulting team is happy to help.

If you would like us to check the status of your Fortinet devices or carry out a broader security review, get in touch or call us on 01452 701355 for a no-obligation chat.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name