Patching is not cleaning: FortiOS and the extra slash
On 27 July, CISA added a FortiOS flaw to its exploited-vulnerabilities catalogue with a deadline attached: 10 August. CVE-2025-68686 opens no new door: it reopens the one Fortinet believed it had closed in April 2025, and it does so with one extra slash in the path. The story of the symbolic link in the language-files folder, the patch that was a string comparison, the 7.2, 7.0 and 6.4 branches left with no fix at all, and why patching is an action while being clean is a conclusion you have to prove.