DEV Community

Cover image for CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

Summary

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

Take Action:

If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)