{
  "id": "CVE-2025-68686",
  "vendor_project": "Fortinet",
  "product": "FortiOS",
  "description": "Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.",
  "kev_date_added": "2026-07-27",
  "cvss": 9.0,
  "severity": "High",
  "advisories": [],
  "cited_in_cases": [],
  "indictment_cited": false
}