Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • Riot Games Login Outage Traced to Expired SSL Certificate
  • Technology

Riot Games Login Outage Traced to Expired SSL Certificate

Do Son January 5, 2026 2 minutes read
0
Riot Games, Certificate Expiration

odified Chrome TLS certificate error page Source: urlscan)

Add Daily CyberSecurity as a preferred source on Google

The well-known game developer Riot Games recently suffered another widespread service disruption after failing to renew an expired digital certificate in time. The certificate in question expired on January 4, 2026, and once it lapsed, all HTTPS connections were rejected.

The immediate consequence was that the League of Legends client could no longer connect to the servers. Notably, this was not the first such incident. Back in January 2016, Riot Games similarly neglected to renew a certificate, and the replacement certificate issued at that time was set to expire in January 2026. A decade ago, Riot employees stated that the certificate would be automatically renewed and that similar issues would not recur. Ten years on, however, it appears the underlying certificate renewal problem remains unresolved.

The client certificate used by Riot is self-signed. In theory, this means Riot could issue a certificate valid for 20 years or even longer. However, longer validity periods increase the risk associated with potential private key compromise, which is why certificates are generally not issued for excessively long durations.

Forgetting to renew digital certificates is, of course, a long-standing and industry-wide problem. Google, Microsoft, and Apple have all experienced similar lapses. Apple, in fact, previously proposed shortening certificate validity periods to just 47 days—a move that ultimately gained industry support.

Under new rules set by the CA/Browser Forum, certificates issued by 2028 will have a maximum validity of only 47 days, excluding root and intermediate certificates. As a result, incidents caused by expired certificates and missed renewals are likely to become increasingly frequent.

Returning to the recent outage, a Riot Games employee reportedly became aware of the expired certificate only after seeing user complaints on Reddit. The employee then coordinated with the technical team to implement an emergency fix, and server connectivity was restored after several hours of downtime.

That said, some players may still encounter “unknown player” messages upon entering the game. Affected users are advised to update the client, restart the application, and ensure that their system clock is set to the correct time.

Related Posts:

  • Riot Games has been hacked: League of Legends and other game source codes stolen
  • League of Legends Fans Targeted: Beware the Lumma Stealer Lurking in Fake Ads!
  • DeepSeek’s Exposed Database Leaks Sensitive User Information
  • Windows Security Alert: Secure Boot Certificates Expiring in 2026, Update Now
  • CVE-2023-33975: RIOT-OS Code Execution Vulnerability

Related coverage

  • Google Developing Dynamic Patching to Update Chrome Without a Restart
  • System76 prepares to develop its own desktop Linux computers
  • The Kill Switch: How an Automated Google Cloud Error Instantly Wiped Out the Railway Platform
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: CA/Browser Forum cybersecurity Digital Trust https League of Legends LoL Login Fix Networking outage Riot Games SSL Certificate

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90680CVSS 9.9
    A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted...
  • CVE-2026-90608CVSS 9.9
    A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element...
  • CVE-2026-90607CVSS 9.9
    A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function...
  • CVE-2026-90606CVSS 9.9
    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue...
  • CVE-2026-90605CVSS 9.9
    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects...
  • CVE-2026-81648CVSS 10.0
    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply...
  • CVE-2026-90558CVSS 9.8
    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting...
  • CVE-2026-78159CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-85681CVSS 9.8
    The WP Component WordPress plugin through 2.2.4 does not have any capability...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.