Fortinet FortiOS: A New Vulnerability Being Actively Exploited (CISA KEV) — On a Compromised Firewall, A Patch Alone Isn't Enough

On July 27, 2026, the U.S. agency CISA added a new vulnerability in FortiOS—the system that runs on FortiGate firewalls, devices used by many small businesses to protect their networks and remote access—to its list of actively exploited vulnerabilities. The vulnerability (CVE-2025-68686) does not open the door to an external attacker from scratch, but it does something just as important: it allows an attacker who has already gained access to the firewall through another vulnerability to bypass the cleanup process and continue reading sensitive data, including configuration files and passwords. In practice, even after applying the fix, residual access may persist.

Context matters. Over the past week, there have been several reports regarding Fortinet firewalls, including leaked administrator passwords from tens of thousands of devices. The message for a company without an in-house IT department is not to panic, but to understand a simple concept: a firewall is a computer at the edge of the network, and if it has ever been compromised, simply updating it is not enough. It must be assumed that whoever gained access was able to copy the configuration and passwords.

  • Update FortiOS to the latest patched version; if you are running an older series (6.4, 7.0, or 7.2), plan to migrate to a supported version.
  • If there is any suspicion that the firewall has been compromised, change the administrator passwords, keys, and certificates—not just on the firewall, but also wherever they were reused.
  • Check for any administrator accounts or access rules that you did not create, and restrict access to the management interface.

For a small business, a quick review of the firewall—version, accounts, passwords, administrative access—closes the very door that this type of vulnerability leaves ajar.

The alert and the analyses on which the article is based:

  • CISA | https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
  • SecurityWeek | https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities/
  • SentinelOne Vulnerability Database | https://www.sentinelone.com/vulnerability-database/cve-2025-68686/

This article was generated with AI assistance.

Request a quote

← All news