Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Important Fortinet FortiOS Security Issue Could Expose Sensitive Information

A security weakness in Fortinet's FortiOS software has been identified that could allow attackers to access sensitive information if they have already compromised the system. This vulnerability is actively being exploited and affects multiple versions of FortiOS, a common network security product.

28 July 2026

Reference: CVE-2025-68686

1. What is being reported?

The report concerns a vulnerability in Fortinet FortiOS software that may let attackers bypass existing security patches and access sensitive data. However, the attacker must first have gained access to the system through another weakness before exploiting this issue.

2. What this means in plain English

If your organisation uses Fortinet FortiOS devices, and an attacker has already broken into your system, they might be able to get more sensitive information than expected. This could increase the damage caused by an initial breach.

3. Could this affect a small business?

Small businesses using Fortinet FortiOS products could be affected, especially if their devices are connected to the internet and not fully updated. Organisations not using Fortinet FortiOS or those with strong network protections are less likely to be impacted.

4. What to do now

  • Check with your IT provider if your Fortinet FortiOS devices are running affected versions.
  • Ensure all FortiOS devices are updated with the latest security patches as per Fortinet’s instructions.
  • Review your network for any signs of compromise or unusual activity.
  • Follow guidance from your IT provider on applying mitigations or consider discontinuing use if updates are unavailable.

5. Ask your IT provider

Can you confirm if our Fortinet FortiOS devices are affected by CVE-2025-68686 and whether all recommended patches and mitigations have been applied?

6. Bottom line

Keep your Fortinet FortiOS devices fully updated and monitor for any signs of compromise to reduce the risk from this known exploited vulnerability.

Information sourced from CISA KEV, NVD and reputable security reporting.

Back to Vulnerability Briefs