First Source
Cybersecurity · July 28, 2026
CISA KEV catalog v2026.07.27 · CVE-2025-68686 · added July 27 · remediation due August 10 · vendor advisory FG-IR-25-934, last updated March 12

Yesterday CISA added a FortiOS flaw to the catalog it reserves for vulnerabilities under active attack. The vendor page it links to rates the same bug Medium, five point three, and answers “Known Exploited” with one word: No.

Every patch queue in the mid-market is a sorting problem. Something dumps a few thousand findings into a list, the list sorts by score, and a human works down from the top until the week ends. That is not negligence. It is the only way anyone gets through it.

Which means the score is not a description of risk. It is the thing that decides whether a person ever looks.

So: on July 27 CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog — the list whose entire admission criterion is evidence that attackers are using it. Remediation due August 10. Then follow the link CISA itself puts in the entry, over to Fortinet’s advisory, and read the box on the right.

Medium·5.3·No

Severity · CVSSv3 Score · Known Exploited — the three fields on Fortinet's PSIRT page for FG-IR-25-934, read this morning

Page last updated March 12, 2026 — four months before CISA's catalog said otherwise.

I want to be fair about this, because “vendor downplays bug” is a lazy story and it is not the one here. Fortinet published this in February, described it accurately, and the page has simply not been touched since March. CISA got new information in July. The two documents disagree because one of them stopped.

But your scanner does not know that. It ingests a number. And a 5.3 marked Medium, with information disclosure as the impact, is exactly the finding that survives a triage pass untouched — every week, forever, until someone notices it has a federal due date attached.

Now read what the bug actually does, because this is the part that reframes the whole thing.

Verbatim, the CISA KEV catalog entry for CVE-2025-68686
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Read that last sentence again. This flaw is not how anyone gets in. It only works on a box somebody already owns. It defeats the patch that was supposed to remove their persistence.

Which tells you what CISA’s decision actually means. You do not put a post-exploitation bug on the actively-exploited list because attackers are breaking in with it. You put it there because they are still inside — on firewalls whose owners patched, closed the ticket, and believe the incident is over.

That is the sentence I would carry into a client conversation this week. Not “there is a new Fortinet CVE.” It is: the federal government just published evidence that the cleanup didn’t take.

5.3
the CVSS v3 score on the vendor’s page — the number your queue sorts on. The score Fortinet submitted to NVD as the CNA is 5.9. Both are Medium; neither is a reason anyone looks
Aug 10
the KEV remediation due date. The required action also invokes CISA’s Forensics Triage Requirements — not just patch it, but establish whether you were compromised before you did
3
FortiOS trains listed as affected in all versions — 7.2, 7.0 and 6.4. The fixed builds exist only in the 7.4 and 7.6 lines, so for those three the remedy is a migration, not a patch

The catalog's own field for ransomware use reads "Unknown." Nobody should be told this is ransomware. It is worse in a quieter way — it is persistence.

The scope limiter, which is real and which you should lead with, not bury

Fortinet’s advisory carries a sentence that takes a large number of boxes off the table immediately: “Products that never had SSL-VPN enabled, are not impacted by this issue.” The affected component is named on the page as SSL-VPN. If a client never turned it on, they are out, and telling them so plainly is worth more than a scary email — it is the difference between an advisor and an alarm. The trouble is the word never. A FortiGate that ran SSL-VPN for two years, got migrated to a different remote-access setup, and had the feature switched off is not covered by that sentence, and neither is one where nobody left is sure. The honest version of this check is a configuration history, not a config screenshot.

Sort by KEV membership, not by severity — once, this week
The specific move: pull the KEV catalog (CISA publishes it as JSON, free, no login) and join it against your own findings on the CVE id. Anything that is in the catalog and sitting in your queue below the line where humans stop reading is your list. This one will be on it. Most shops have never run that join, and it takes an afternoon to build and then runs forever.
For every FortiGate in scope, ask the question the due date is really asking
The KEV required action does not stop at remediation — it points to CISA’s Forensics Triage Requirements. Given that this bug only functions on an already-compromised device, the useful question is not “are we patched.” It is: was this firewall ever compromised, was the cleanup verified by something other than the patch being applied, and were the credentials that lived on it rotated afterward. If the answer to the last one is no, the patch level is not the finding.
Screenshot the vendor page today, with the date visible
Fortinet may well update FG-IR-25-934 — it should, and this edition may be describing a page that no longer reads this way by the time you check. That is the point rather than a caveat: if you are going to tell a client that their tooling under-rated something, the artifact that makes the case is the vendor page as it stood while their scanner was reading it. Capture it now. It is evidence with a shelf life measured in days.
Aug 10

CVE-2025-68686 carries a KEV remediation due date of August 10, 2026, thirteen days after it was added. That date is binding on federal civilian executive branch agencies only — it is not a legal obligation for a private company, and anyone told otherwise is being sold something. What it is, for everyone else, is a published federal judgment about how urgent this is, dated, citable, and sitting in direct contradiction to a 5.3.

Kept honest: the vendor is not hiding anything. Fortinet published this advisory on February 10, 2026 and last updated it March 12; the “Known Exploited: No” and the 5.3 are what that page said when it was written and nobody has been back since. CISA added the CVE on July 27 on newer information. Both documents can be accurate on their own dates — the failure is that a scanner reads one of them and not the other. Everything quoted from the PSIRT page is timestamped to a fetch made the morning of July 28, 2026 and may already have changed; re-check before you repeat it. This vulnerability is post-exploitation only — an attacker must already have compromised the device by other means, so it is not a remote break-in and should never be described as one. The KEV catalog records ransomware use as “Unknown,” so no ransomware claim is available. The August 10 date binds FCEB agencies under BOD 26-04, not the private sector. The affected-version list quoted — “FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions” — is NVD’s, and the inference that the three “all versions” trains have no fixed build is drawn from the fixed ranges, not from a vendor statement. The reading that a post-exploitation bug entering KEV implies live persistence in the field is mine; CISA states the exploitation evidence, not that interpretation.

Sources (primary, verified this morning): CISA, Known Exploited Vulnerabilities Catalog, catalogVersion 2026.07.27 (1,655 entries) — the CVE-2025-68686 record, its dateAdded of 2026-07-27, its dueDate of 2026-08-10, its requiredAction and its “Unknown” ransomware field were read from that JSON directly. The vendor text is Fortinet PSIRT advisory FG-IR-25-934, published February 10, 2026, updated March 12, 2026, fetched at approximately 8:20 a.m. eastern on July 28, 2026 — the Severity, CVSSv3 Score and Known Exploited fields are quoted as that page rendered at that moment. The affected-version language and the CNA score of 5.9 are from the NVD record for CVE-2025-68686, which also carries cisaExploitAdd 2026-07-27 and cisaActionDue 2026-08-10. The remediation-timeline framework is CISA BOD 26-04, cited in the catalog entry’s own required action. No security trade press supplied any fact in this edition.

Meschelle Peterson
code63labs

LinkedIn-ready text

Yesterday CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog. That catalog has exactly one admission criterion: evidence of active exploitation. Remediation due August 10.

Follow the link CISA puts in its own entry, over to Fortinet's advisory FG-IR-25-934, and read the fields on the right:

Severity: Medium
CVSSv3 Score: 5.3
Known Exploited: No

That page was last updated March 12, 2026.

Before anyone reaches for "vendor downplays bug" — that's not the story. Fortinet published this in February, described it accurately, and hasn't touched the page since March. CISA got new information in July. The two documents disagree because one of them stopped.

But your scanner doesn't know that. It ingests a number.

And a 5.3 / Medium / information disclosure is precisely the finding that survives a triage pass untouched. Every week. Forever. Because every patch queue in the mid-market is a sorting problem — a few thousand findings, sorted by score, worked top-down until the week ends. The score isn't a description of risk. It's what decides whether a human ever looks.

Now the part that reframes it. CISA's own description of the bug:

"This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level."

Read the last sentence again.

This is not how anyone gets in. It only works on a box somebody already owns. It defeats the patch that was supposed to remove their persistence.

So think about what putting THAT on the actively-exploited list means. You don't flag a post-exploitation bug because attackers are breaking in with it. You flag it because they're still inside — on firewalls whose owners patched, closed the ticket, and believe the incident is over.

That's the sentence I'd carry into a client conversation this week. Not "there's a new Fortinet CVE." It's: the federal government just published evidence that the cleanup didn't take.

The scope limiter, which deserves to lead and not be buried — Fortinet's page says plainly: "Products that never had SSL-VPN enabled, are not impacted by this issue." If a client never turned it on, they're out, and telling them that plainly is worth more than a scary email.

The trouble is the word NEVER. A FortiGate that ran SSL-VPN for two years, got migrated, and had it switched off isn't covered by that sentence. That check is a configuration history, not a screenshot.

Three things worth doing:

1. Sort by KEV membership, not severity — once. CISA publishes the catalog as JSON, free, no login. Join it against your own findings on the CVE id. Anything in the catalog sitting below the line where humans stop reading is your list. Takes an afternoon to build, runs forever.

2. Ask what the due date is really asking. The required action points to CISA's Forensics Triage Requirements. Given this bug only functions on an already-compromised device: was this firewall ever compromised, was cleanup verified by something other than the patch being applied, and were the credentials on it rotated. If the last answer is no, patch level isn't the finding.

3. Screenshot the vendor page today, with the date visible. Fortinet may well update it — it should. If you're going to tell a client their tooling under-rated something, the artifact that makes the case is the page as it stood while their scanner was reading it.

Keeping it honest: post-exploitation only — not a remote break-in, don't describe it as one. Ransomware use in the catalog reads "Unknown." The August 10 date binds federal civilian agencies under BOD 26-04, not private companies; anyone telling you otherwise is selling something. And every quote from the vendor page is timestamped to a fetch this morning and may already read differently.

Sources: CISA KEV catalog v2026.07.27; Fortinet FG-IR-25-934; NVD CVE-2025-68686.

Your narrated animation

A finished, narrated animation of this edition came with your email (MP4, 1080×1350 — sized for LinkedIn and Instagram). Post it as-is.

FIRST SOURCE · one verified original-source finding, composed for one reader · this edition: cybersecurity — written for the MSPs, vendors and consultancies whose clients run a scanner that sorts by a number nobody has re-checked