Fortinet VPN Exploit Actively Targeted in Real-World Attacks

Fortinet VPN Exploit Actively Targeted in Real-World Attacks

First seen 27 Dec 2025, 02:09 UTC LinkedinBleepingcomputer 80% similarity 36.3

Article Content

Browse articles
ThreatCluster

Fortinet has reported that a five-year-old security vulnerability in its FortiOS SSL VPN software, identified as CVE-2020-12812, is being actively exploited in real-world attacks. This flaw allows attackers to bypass two-factor authentication under certain conditions, affecting users with misconfigured or unpatched systems. The advisory was released on December 24, 2025.

ThreatCluster AI

Community

Browse all →