CISA Alerts on Fortinet FortiOS Vulnerability Amid Active Exploitation
The Cybersecurity and Infrastructure Security Agency (CISA) has added the Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities catalog, following evidence of active attacks. This vulnerability affects Fortinet's FortiOS, used in FortiGate firewalls, and is classified as an exposure of sensitive information to unauthorized actors. The flaw allows remote attackers to bypass security patches via crafted HTTP requests, provided they have already compromised the system through another vulnerability. CISA has mandated that Federal Civilian Executive Branch agencies apply necessary mitigations by August 10, 2026, and has advised organizations to follow Fortinet's guidance to address the issue.