{"id":6431,"date":"2026-01-05T17:44:55","date_gmt":"2026-01-05T17:44:55","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=6431"},"modified":"2026-01-05T17:44:55","modified_gmt":"2026-01-05T17:44:55","slug":"ten-thousand-firewalls-are-vulnerable-to-old-vulnerability","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=6431","title":{"rendered":"Ten thousand firewalls are vulnerable to old vulnerability"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks\/\" target=\"_blank\" rel=\"noopener\">Bleeping Computer<\/a> reports that hackers are exploiting an old vulnerability in FortiOS that can be used to get around the <a href=\"https:\/\/www.csoonline.com\/article\/563753\/two-factor-authentication-2fa-explained.html\">two-factor authentication<\/a> (2FA) requirement.<\/p>\n<p>The vulnerability, designated CVE-2020-12812, was patched back in July 2020, but five and a half years later, there are still at least 10,000 firewalls that have not been updated.<\/p>\n<p>To be on the safe side, all users of FortiOS and Fortigate are therefore urged to install the latest updates as soon as possible.<\/p>\n<p><em>This news brief originally appeared on <a href=\"https:\/\/computersweden.se\/article\/1312695\/kritisk-sarbarhet-i-fortios.html\">ComputerSweden<\/a>.<\/em><\/p>\n<p>More Fortinet security news:<\/p>\n<p><a href=\"https:\/\/www.csoonline.com\/article\/4107440\/fortigate-firewall-credentials-being-stolen-after-vulnerabilities-discovered.html\">FortiGate firewall credentials being stolen after vulnerabilities discovered<\/a><\/p>\n<p><a href=\"https:\/\/www.csoonline.com\/article\/4093949\/fortinet-criticized-for-silent-patching-after-disclosing-second-zero-day-vulnerability-in-same-equipment.html\">Fortinet criticized for \u2018silent\u2019 patching after disclosing second zero-day vulnerability in same equipment<\/a><\/p>\n<p><a href=\"https:\/\/www.csoonline.com\/article\/4104499\/fortinet-admins-urged-to-update-software-to-close-forticloud-sso-holes.html\">Fortinet admins urged to update software to close FortiCloud SSO holes<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Bleeping Computer reports that hackers are exploiting an old vulnerability in FortiOS that can be used to get around the two-factor authentication (2FA) requirement. The vulnerability, designated CVE-2020-12812, was patched back in July 2020, but five and a half years later, there are still at least 10,000 firewalls that have not been updated. To be [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":6432,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-6431","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/6431"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6431"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/6431\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/6432"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6431"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6431"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6431"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}