Home / Insights / Article

// Darksteel Insights · 2026-07-28

SMBs: Critical FortiOS Vulnerability CVE-2025-68686 Is Being Exploited

A critical vulnerability in Fortinet FortiOS is being actively exploited. SMBs must act now to protect sensitive data.

The short version
  • CVE-2025-68686 is a critical FortiOS vulnerability that exposes sensitive information to attackers.
  • SMBs using Fortinet firewalls are at risk and must patch immediately.
  • Check your FortiOS version and apply the latest security update from Fortinet.
  • Contact your IT provider to confirm if you’re affected and to remediate.

What is CVE-2025-68686, and why should I care?

CVE-2025-68686 is a critical vulnerability in Fortinet’s FortiOS, the software that runs on Fortinet firewalls. This flaw allows attackers to access sensitive information that should be protected, such as credentials or internal network details. Because it’s already being exploited in the wild, this is not a hypothetical risk — it’s a real and present danger for small and mid-sized businesses.

The vulnerability is rated high severity by CISA and has been added to their Known Exploited Vulnerabilities (KEV) catalog. This means that threat actors are actively using it to break into systems, often to steal data or set up backdoors for future attacks. For SMBs, this could lead to data breaches, compliance violations, and costly downtime.

Even if you don’t know much about FortiOS, it’s important to understand that if your business uses a Fortinet firewall — which is common in many SMBs — you are at risk. The good news is that a fix is available, but you must act quickly to apply it.

How does this vulnerability affect small and mid-sized businesses?

If your business uses a Fortinet firewall with an affected version of FortiOS, attackers could exploit this vulnerability to access internal network data. This includes sensitive information like usernames, passwords, or internal IP addresses. Once inside, attackers can move laterally through your network, steal data, or set up long-term access for future attacks.

SMBs are particularly vulnerable because they often lack the resources or expertise to detect and respond to such attacks in real time. This makes them a prime target for cybercriminals who are looking for the easiest path to valuable data.

In the worst-case scenario, an attacker could gain access to your systems and steal customer or employee data. This could result in legal penalties, loss of customer trust, and expensive remediation efforts.

What should I do this week to protect my business?

First, determine if your business is using a Fortinet firewall and check the version of FortiOS you are running. You can find the version in your firewall’s system settings or by logging into the Fortinet support portal. If you’re unsure, contact your IT provider or Fortinet support directly.

If you are running an affected version of FortiOS, apply the latest security patch from Fortinet immediately. Fortinet has released updates that address this vulnerability, and you can find them on their official website. Applying the patch is the most critical step to prevent attackers from exploiting this flaw.

In addition to patching, review your firewall logs for any unusual activity. Look for signs of unauthorized access or unexpected traffic patterns. If you see anything suspicious, isolate the affected systems and contact a cybersecurity expert for further analysis.

How can I tell if my business has already been compromised?

Detecting a breach can be difficult, but there are some signs to watch for. Unusual login attempts, especially from unknown IP addresses or during off-hours, could indicate that someone has gained access. You may also notice unexpected data transfers, such as large files being sent out of your network or strange DNS queries.

Another red flag is if your firewall logs show repeated failed login attempts or if you receive alerts from your antivirus or endpoint protection software. These could be signs that an attacker is trying to exploit the vulnerability or has already done so.

If you suspect that your systems have been compromised, the first step is to disconnect the affected systems from the network to prevent the attacker from spreading further. Then, contact a cybersecurity professional to perform a thorough investigation and clean up any malware or backdoors that may have been installed.

Not sure whether your environment is exposed? That is exactly what our Vulnerability Management service is built to surface. Talk to us.

Frequently asked questions

What is FortiOS, and why is it important for my business?
FortiOS is the operating system that powers Fortinet firewalls, which are used by many businesses to protect their networks from cyber threats. It acts as a gatekeeper, filtering traffic and blocking malicious activity. If FortiOS is compromised, attackers can bypass these protections and access sensitive data.
Do I need to replace my Fortinet firewall if I apply the patch?
No, applying the patch is sufficient to fix the vulnerability. Fortinet has released updates for affected versions of FortiOS, and you can apply them through the firewall’s management interface. There is no need to replace your hardware unless it is outdated or no longer supported.
How long do I have to fix this vulnerability?
CISA has set a remediation deadline of August 10, 2026, for federal agencies, but SMBs should act as soon as possible. The longer you wait, the higher the risk of being exploited. Apply the patch now to protect your business.
Can I check if I’m affected without contacting Fortinet?
You can check your FortiOS version in your firewall’s system settings or through the Fortinet support portal. If the version is listed as affected in the CVE-2025-68686 advisory, you should apply the patch immediately. If you’re unsure, contact your IT provider or Fortinet support for help.
What if I don’t use Fortinet firewalls?
If your business doesn’t use Fortinet firewalls, this vulnerability does not affect you. However, it’s still a good idea to ensure that all your network devices are up to date and properly configured to protect against other threats.

Source (public domain): CISA