Fortinet's FortiOS had two vulnerabilities confirmed exploited in 2026, both disclosed to NVD in early 2026 and both spanning a wide range of FortiOS versions — a reminder that a vulnerability's severity score and its real-world urgency don't always move together.
CVE-2025-25249, CVSS 8.1, added to KEV 9 September 2026, is a heap-based buffer overflow spanning FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17, and all versions of 6.4. CVE-2025-68686, CVSS 5.9, added 27 July 2026, is an exposure of sensitive information to an unauthorized actor, spanning FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, and all of 7.2.
Breadth of affected versions as its own signal
Both CVEs list version ranges spanning several major FortiOS release lines — not one recent branch, but the accumulated history of supported versions going back years. A heap-based buffer overflow or an information-exposure bug present across that many release lines typically indicates the vulnerable code has existed, largely unchanged, through multiple feature releases — meaning the vulnerability was not introduced by a recent change and then quickly caught, but sat present through a long stretch of the product's active life before being found.
That has a direct practical consequence for any organisation running FortiOS: the affected range is wide enough that "we're not on the latest version, but we're not that far behind either" is not a safe assumption to make about either CVE without checking the specific ranges named.
Why the lower-severity CVE still deserves attention
CVE-2025-68686's CVSS 5.9 is meaningfully lower than the 8.1 of its companion, and information-exposure bugs are frequently deprioritised relative to code-execution or buffer-overflow findings for exactly that reason. But an information disclosure on a firewall operating system is rarely disclosure of harmless data — a security appliance's own sensitive information is disproportionately likely to include configuration details, session state, or credential material that meaningfully aids a subsequent, more damaging attack. Read alongside CVE-2025-25249, a plausible chain exists: information exposure providing reconnaissance, buffer overflow providing the exploitation path.
Firewall patch cycles are structurally slower, and that gap is the actual risk
Applying a FortiOS update on production firewall infrastructure carries real operational risk — a botched update or unexpected behavioural change on a device mediating all network traffic can cause an outage far more disruptive than patching an individual application server. That legitimate caution is precisely why firewall operating systems tend to lag behind other infrastructure categories in patch currency, and precisely why a wide affected-version range like the one CVE-2025-25249 carries matters more in practice than it would for software patched on a faster, lower-risk cadence.
What to check this week
Check your FortiOS version against both affected ranges specifically, not against a general sense of how current your deployment is. Both ranges span multiple major release lines.
Do not deprioritise CVE-2025-68686 solely on its CVSS score. Information exposure on the firewall operating system itself is a different risk category than information exposure in an application, precisely because of what a firewall's own state typically contains.
Confirm patch application actually completed, rather than assuming a scheduled maintenance window addressed it. FortiOS updates on production firewall infrastructure are sometimes deferred specifically because of the operational risk of a firewall outage, which can leave a "planned" patch indefinitely pending.
The general takeaway for firewall operating systems as a category
Fortinet is far from alone in producing firewall-OS CVEs with wide affected-version ranges — the pattern recurs across every major firewall vendor, precisely because the operational caution that governs firewall patch cycles is an industry-wide constraint, not a Fortinet-specific one. Any organisation running perimeter security infrastructure from any vendor should read these two CVEs as a prompt to audit its own firewall patch currency directly, rather than assume its own vendor relationship is exempt from the same structural lag.
One more question worth asking your firewall team directly
Ask specifically when the last FortiOS update was applied and what the current running version is, by device — a general "we're current" answer from memory is exactly the kind of unverified confidence a wide affected-version range like this one is built to slip past.
How Safeguard helps
Safeguard's continuous inventory tracks the exact version and affected-range status of security appliances like firewalls, distinguishing "current enough" from "verified past the specific vulnerable range" — a distinction that matters most when, as here, the affected range spans years of releases and a general sense of currency isn't sufficient confirmation.