Bleepingcomputer
Fortinet VPN Exploit Actively Targeted in Real-World Attacks
First seen 27 Dec 2025, 02:09 UTC
•
•36.3
Export
Article Content
Browse articles
Fortinet has reported that a five-year-old security vulnerability in its FortiOS SSL VPN software, identified as CVE-2020-12812, is being actively exploited in real-world attacks. This flaw allows attackers to bypass two-factor authentication under certain conditions, affecting users with misconfigured or unpatched systems. The advisory was released on December 24, 2025.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
EU Sanctions Iranian Cyber Group for Election Interference and Data Breaches
cPanel and WHM Critical Auth Bypass Vulnerability Patched
US and Allies Dismantle Major IoT Botnets Behind Record DDoS Attacks