Observed Signal · Jul 28, 2026 · Vulnerability Disclosure · Source: DEV Community · Impact: 4/5 · Sentiment: Negative
FortiOS CVE-2025-68686 Symlink Mitigation Bypass
CVE-2025-68686 is an actively exploited FortiOS vulnerability that allows attackers who already have file-system access to bypass symlink persistence mitigations via crafted HTTP requests to the SSL‑VPN web interface. The flaw can expose sensitive files (configurations, credentials, keys) even after firmware upgrades. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026. Affected FortiOS versions include 6.4, 7.0, 7.2, 7.4.0–7.4.6 and 7.6.0–7.6.1; vendor fixes are available in 7.4.7, 7.6.2 or later. Successful exploitation requires a prior file‑system compromise; remediation guidance includes rebuilding devices, removing artifacts, rotating secrets, and restricting SSL‑VPN exposure.
CISA added an actively exploited FortiOS vulnerability to its KEV catalog; it affects widely deployed perimeter devices (FortiGate) and can expose credentials and keys, requiring urgent incident response and potential device rebuilds.
Track Fortinet Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- CVE-2025-68686 allows bypass of symlink persistence mitigations in FortiOS via crafted HTTP requests to the SSL‑VPN interface.
- CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026.
- Affected FortiOS versions: 6.4, 7.0, 7.2, 7.4.0–7.4.6, and 7.6.0–7.6.1; fixed in 7.4.7, 7.6.2 or later (vendor table referenced).
- Exploit is actively used in the wild and requires the attacker to have prior file system compromise on the device.
- The article reports a CVSS score of 5.9 and classifies the issue as critical in practical risk due to persistence of symlink artifacts.
Connected Companies & Entities
1 Entity mapped“Initial compromise and symlink placement happen on the FortiGate/FortiOS device....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
OpenClaw SSH Sandbox Symlink Escape Vulnerability
A critical symbolic-link handling vulnerability (GHSA-FV94-QVG8-XQPW) was disclosed in the OpenClaw AI agent framework affecting versions 2026.3.28 and earlier. The flaw resides in the uploadDirectoryToSshTarget component and fails to validate symlinks before uploading, enabling an attacker interacting with an AI agent to traverse directory boundaries and perform arbitrary local file reads or arbitrary writes on remote SSH sandbox hosts. The issue carries a CVSS v3.1 score of 8.8 and is currently demonstrated by a proof-of-concept. The vulnerability was fixed in openclaw release 2026.3.31 (commit 3d5af14), which adds symlink validation via assertSafeUploadSymlinks and resolves boundary path checks. Recommended mitigations include upgrading to >=2026.3.31, enabling human-in-the-loop review, enforcing least-privilege SSH accounts, and implementing filesystem monitoring.
Cisco patches CVSS 10.0 Secure Workload authentication bypass
Cisco released emergency patches addressing a maximum-severity authentication-bypass vulnerability in its Secure Workload platform (tracked as CVE-2026-20223) that earned a CVSS 10.0 score. The flaw allows unauthenticated remote attackers to gain Site Admin privileges by sending specially crafted requests to Secure Workload's REST API, bypassing authentication. The vulnerability affects both SaaS-hosted and on-premises deployments, can enable cross-tenant access to sensitive telemetry and configuration, and has no known workaround — Cisco recommends applying the fixes immediately. Security publishers noted this is one of several 'perfect 10' bugs disclosed for Cisco in 2026 and emphasized the broad impact on enterprises that use Secure Workload as part of zero-trust and micro-segmentation architectures.
Critical Arista VeloCloud Orchestrator RCE (CVE-2026-16812)
Arista disclosed CVE-2026-16812, a CVSS 10.0 operating-system command injection in on-premises VeloCloud Orchestrator (VCO) that is being actively exploited. Successful exploitation can give remote attackers privileged control of the orchestrator and potentially the VeloCloud Edge devices it manages. Arista published fixed on-prem builds (5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1), advised network blocks for three IoC IPs (8.19.75.217, 206.72.242.124, 206.72.242.162), and recommended restricting VCO web access and preserving logs for forensic analysis. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a July 30, 2026 FCEB patch deadline. The article also notes related KEV additions for Fortinet FortiOS (CVE-2025-68686) and Alibaba Fastjson (CVE-2026-16723).
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
