Critical Analysis: CVE-2025-68686 - Fortinet FortiOS Exposure of Sensitive Information to an Una... — July 31, 2026

Published 31 Jul 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

AGMP Partners Initial Discovery and Context Today, July 31, 2026, Fortinet released a critical advisory concerning CVE-2025-68686, detailing a severe exposure of sensitive information vulnerability within specific versions of FortiOS. My team at AGMP has been tracking pre-release disclosures on this for weeks, and frankly, it’s a bad one. This particular flaw, classified with a CVSS v3.1 base score of 9.1 (Critical), specifically targets the authentication and session management components of FortiOS, leading to unauthorized access to configuration data, session tokens, and potentially decrypted traffic. This isn't just about a config file here or there; we’re talking about components foundational to network perimeter security. The affected versions include FortiOS 7.0.0 through 7.0.12, 7.2.0 through 7.2.7, 7.4.0 through 7.4.2, and FortiProxy 7.2.0 through 7.2.6, and 7.4.0 through 7.4.1.