Single-sign-on accounts are used for Fortinet websites such as support.fortinet.com and forticloud.com. Many other Fortinet sites use the same login.
![]()

Single-sign-on accounts are used for Fortinet websites such as support.fortinet.com and forticloud.com. Many other Fortinet sites use the same login.
![]()

Last Update: 06.02.2026 … or accessed from any unauthorized party. In some cases it’s not even necessary to hack a system to gain access to it. For example it may be enough to leak a configuration file to allow unauthorized system access. Fortunately, many cases of a suspected hack turn…
![]()

Fortinet has changed it’s SSO system underneith. Therefore, the shown message has changed. We have documented the new behaviour in this blog post: https://blog.boll.ch/fortinet-account-your-account-has-been-locked/ The single-sign-on accounts for Fortinet websites are used for sites such as support.fortinet.com and forticloud.com. There are a whole lot of other sites that use the…
![]()

If you are not using your account for PSAT admin access on a regular basis, your account will get locked down automatically after 92 days (this is a default value that can be adjusted). Accounts are also being locked after 5 unsuccessfull login attempts by default. To unlock your account,…
![]()

There seems to be a vulnerarbility in some FortiMail versions, that allow an unauthenticated remote attacker to access the system by requesting a password change. Please refer to the FortiGuard PSIRT article. The problem here is not only the unauthorized access to the system, but also the change of the…
![]()
Sind Sie interessiert, den BOLL Blog als RSS Feed zu abonnieren?