Executive brief
Fortinet FortiOS, the operating system powering FortiGate firewalls, contains a vulnerability that could allow an attacker to maintain access to a compromised system. This flaw specifically allows an attacker to bypass previous security patches intended to prevent malicious files from persisting on the device. To exploit this, an attacker must have already gained initial access to the device's file system through a separate security weakness.
Technical details
An Exposure of Sensitive Information vulnerability (CWE-200) exists in multiple versions of Fortinet FortiOS. The flaw allows a remote unauthenticated attacker to bypass security patches designed to mitigate symbolic link persistency mechanisms used in post-exploitation scenarios. Exploitation is achieved via crafted HTTP requests. A critical precondition is that the attacker must have already compromised the target device at the filesystem level via a separate vulnerability. This vulnerability has been observed in active exploitation as a means of maintaining persistence on compromised network appliances.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions
Timeline
- 2026-02-10: disclosed: Initial CVE entry created by Fortinet
- 2026-07-27: advisory: NVD record updated with CISA enrichment data
- 2026-07-27: kev added: CISA added to Known Exploited Vulnerabilities catalog