Bleepingcomputer
Fortinet VPN Exploit Actively Targeted in Real-World Attacks
First seen 27 Dec 2025, 02:09 UTC
•
•80% similarity
•36.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Fortinet has reported that a five-year-old security vulnerability in its FortiOS SSL VPN software, identified as CVE-2020-12812, is being actively exploited in real-world attacks. This flaw allows attackers to bypass two-factor authentication under certain conditions, affecting users with misconfigured or unpatched systems. The advisory was released on December 24, 2025.
ThreatCluster AI