SB2026021047 - SSL-VPN symlink persistence patch bypass in FortiOS 



SB2026021047 - SSL-VPN symlink persistence patch bypass in FortiOS

Published: February 10, 2026

Security Bulletin ID SB2026021047
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2025-68686)

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by FortiOS SSL-VPN. A remote user can send a specially crafted HTTP request to bypass the patch developed for the symbolic link persistency mechanism and gain unauthorized access to sensitive information.

Note, the vulnerability is being exploited in the wild in conjunction with other vulnerabilities that provide access at filesystem level.


Remediation

Install update from vendor's website.