Every patch queue in the mid-market is a sorting problem. Something dumps a few thousand findings into a list, the list sorts by score, and a human works down from the top until the week ends. That is not negligence. It is the only way anyone gets through it.
Which means the score is not a description of risk. It is the thing that decides whether a person ever looks.
So: on July 27 CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog — the list whose entire admission criterion is evidence that attackers are using it. Remediation due August 10. Then follow the link CISA itself puts in the entry, over to Fortinet’s advisory, and read the box on the right.
Severity · CVSSv3 Score · Known Exploited — the three fields on Fortinet's PSIRT page for FG-IR-25-934, read this morning
Page last updated March 12, 2026 — four months before CISA's catalog said otherwise.
I want to be fair about this, because “vendor downplays bug” is a lazy story and it is not the one here. Fortinet published this in February, described it accurately, and the page has simply not been touched since March. CISA got new information in July. The two documents disagree because one of them stopped.
But your scanner does not know that. It ingests a number. And a 5.3 marked Medium, with information disclosure as the impact, is exactly the finding that survives a triage pass untouched — every week, forever, until someone notices it has a federal due date attached.
Now read what the bug actually does, because this is the part that reframes the whole thing.
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Read that last sentence again. This flaw is not how anyone gets in. It only works on a box somebody already owns. It defeats the patch that was supposed to remove their persistence.
Which tells you what CISA’s decision actually means. You do not put a post-exploitation bug on the actively-exploited list because attackers are breaking in with it. You put it there because they are still inside — on firewalls whose owners patched, closed the ticket, and believe the incident is over.
That is the sentence I would carry into a client conversation this week. Not “there is a new Fortinet CVE.” It is: the federal government just published evidence that the cleanup didn’t take.
The catalog's own field for ransomware use reads "Unknown." Nobody should be told this is ransomware. It is worse in a quieter way — it is persistence.
Fortinet’s advisory carries a sentence that takes a large number of boxes off the table immediately: “Products that never had SSL-VPN enabled, are not impacted by this issue.” The affected component is named on the page as SSL-VPN. If a client never turned it on, they are out, and telling them so plainly is worth more than a scary email — it is the difference between an advisor and an alarm. The trouble is the word never. A FortiGate that ran SSL-VPN for two years, got migrated to a different remote-access setup, and had the feature switched off is not covered by that sentence, and neither is one where nobody left is sure. The honest version of this check is a configuration history, not a config screenshot.
CVE-2025-68686 carries a KEV remediation due date of August 10, 2026, thirteen days after it was added. That date is binding on federal civilian executive branch agencies only — it is not a legal obligation for a private company, and anyone told otherwise is being sold something. What it is, for everyone else, is a published federal judgment about how urgent this is, dated, citable, and sitting in direct contradiction to a 5.3.
Kept honest: the vendor is not hiding anything. Fortinet published this advisory on February 10, 2026 and last updated it March 12; the “Known Exploited: No” and the 5.3 are what that page said when it was written and nobody has been back since. CISA added the CVE on July 27 on newer information. Both documents can be accurate on their own dates — the failure is that a scanner reads one of them and not the other. Everything quoted from the PSIRT page is timestamped to a fetch made the morning of July 28, 2026 and may already have changed; re-check before you repeat it. This vulnerability is post-exploitation only — an attacker must already have compromised the device by other means, so it is not a remote break-in and should never be described as one. The KEV catalog records ransomware use as “Unknown,” so no ransomware claim is available. The August 10 date binds FCEB agencies under BOD 26-04, not the private sector. The affected-version list quoted — “FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions” — is NVD’s, and the inference that the three “all versions” trains have no fixed build is drawn from the fixed ranges, not from a vendor statement. The reading that a post-exploitation bug entering KEV implies live persistence in the field is mine; CISA states the exploitation evidence, not that interpretation.
Sources (primary, verified this morning): CISA, Known Exploited Vulnerabilities Catalog, catalogVersion 2026.07.27 (1,655 entries) — the CVE-2025-68686 record, its dateAdded of 2026-07-27, its dueDate of 2026-08-10, its requiredAction and its “Unknown” ransomware field were read from that JSON directly. The vendor text is Fortinet PSIRT advisory FG-IR-25-934, published February 10, 2026, updated March 12, 2026, fetched at approximately 8:20 a.m. eastern on July 28, 2026 — the Severity, CVSSv3 Score and Known Exploited fields are quoted as that page rendered at that moment. The affected-version language and the CNA score of 5.9 are from the NVD record for CVE-2025-68686, which also carries cisaExploitAdd 2026-07-27 and cisaActionDue 2026-08-10. The remediation-timeline framework is CISA BOD 26-04, cited in the catalog entry’s own required action. No security trade press supplied any fact in this edition.
Yesterday CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog. That catalog has exactly one admission criterion: evidence of active exploitation. Remediation due August 10. Follow the link CISA puts in its own entry, over to Fortinet's advisory FG-IR-25-934, and read the fields on the right: Severity: Medium CVSSv3 Score: 5.3 Known Exploited: No That page was last updated March 12, 2026. Before anyone reaches for "vendor downplays bug" — that's not the story. Fortinet published this in February, described it accurately, and hasn't touched the page since March. CISA got new information in July. The two documents disagree because one of them stopped. But your scanner doesn't know that. It ingests a number. And a 5.3 / Medium / information disclosure is precisely the finding that survives a triage pass untouched. Every week. Forever. Because every patch queue in the mid-market is a sorting problem — a few thousand findings, sorted by score, worked top-down until the week ends. The score isn't a description of risk. It's what decides whether a human ever looks. Now the part that reframes it. CISA's own description of the bug: "This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level." Read the last sentence again. This is not how anyone gets in. It only works on a box somebody already owns. It defeats the patch that was supposed to remove their persistence. So think about what putting THAT on the actively-exploited list means. You don't flag a post-exploitation bug because attackers are breaking in with it. You flag it because they're still inside — on firewalls whose owners patched, closed the ticket, and believe the incident is over. That's the sentence I'd carry into a client conversation this week. Not "there's a new Fortinet CVE." It's: the federal government just published evidence that the cleanup didn't take. The scope limiter, which deserves to lead and not be buried — Fortinet's page says plainly: "Products that never had SSL-VPN enabled, are not impacted by this issue." If a client never turned it on, they're out, and telling them that plainly is worth more than a scary email. The trouble is the word NEVER. A FortiGate that ran SSL-VPN for two years, got migrated, and had it switched off isn't covered by that sentence. That check is a configuration history, not a screenshot. Three things worth doing: 1. Sort by KEV membership, not severity — once. CISA publishes the catalog as JSON, free, no login. Join it against your own findings on the CVE id. Anything in the catalog sitting below the line where humans stop reading is your list. Takes an afternoon to build, runs forever. 2. Ask what the due date is really asking. The required action points to CISA's Forensics Triage Requirements. Given this bug only functions on an already-compromised device: was this firewall ever compromised, was cleanup verified by something other than the patch being applied, and were the credentials on it rotated. If the last answer is no, patch level isn't the finding. 3. Screenshot the vendor page today, with the date visible. Fortinet may well update it — it should. If you're going to tell a client their tooling under-rated something, the artifact that makes the case is the page as it stood while their scanner was reading it. Keeping it honest: post-exploitation only — not a remote break-in, don't describe it as one. Ransomware use in the catalog reads "Unknown." The August 10 date binds federal civilian agencies under BOD 26-04, not private companies; anyone telling you otherwise is selling something. And every quote from the vendor page is timestamped to a fetch this morning and may already read differently. Sources: CISA KEV catalog v2026.07.27; Fortinet FG-IR-25-934; NVD CVE-2025-68686.
A finished, narrated animation of this edition came with your email (MP4, 1080×1350 — sized for LinkedIn and Instagram). Post it as-is.
FIRST SOURCE · one verified original-source finding, composed for one reader · this edition: cybersecurity — written for the MSPs, vendors and consultancies whose clients run a scanner that sorts by a number nobody has re-checked