Filed under: Cybersecurity — Patching — July 2026
What happened
Fortinet’s FortiGate firewalls had a nasty bug last year: attackers who broke in could plant a symbolic link that let them keep reading files on the device even after the security hole was patched. Fortinet issued a fix for that persistence trick too — but researchers just found a way around it by adding an extra slash into the web request, and CISA confirmed on July 27, 2026 that criminals are actively using this bypass in the wild (CVE-2025-68686). It only works on a device that was already compromised at some point, but it means old infections can survive a patch that was supposed to clean things up.
Why it matters to your business
FortiGate is one of the most common firewall brands sitting at the edge of small business networks here in Phoenix, and it’s the same product line involved in a wave of stolen VPN credentials we flagged a few weeks ago. If your firewall was ever compromised — even briefly, even a while back — this bug means attackers could still have a quiet foothold today, patch or no patch. That foothold is exactly how ransomware crews get back in after a business thinks it’s cleaned up.
What to do this week
Update FortiOS to the latest patched build (7.6.2, 7.4.7, or the current release for your version — check under System > Firmware in the FortiGate admin console). Don’t stop at patching: if your device runs any FortiOS version between 6.4 and 7.6.1 and has internet-facing SSL-VPN, have your IT provider check system logs and running config for unfamiliar admin accounts, scheduled tasks, or config changes you don’t recognize. If you’re not sure whether your firewall has ever been compromised, that’s worth a professional look rather than a guess.
The bigger picture
This is the second Fortinet-related warning for SMBs in a month — a reminder that patching alone doesn’t undo a break-in that already happened. — U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Not sure if your firewall has been checked for hidden footholds? Book a free consult — https://micro1tech.com/contact/