Skip to content
June 2, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Technology
  • Riot Games Login Outage Traced to Expired SSL Certificate
  • Technology

Riot Games Login Outage Traced to Expired SSL Certificate

Ddos January 5, 2026 2 minutes read
0
Riot Games, Certificate Expiration

odified Chrome TLS certificate error page Source: urlscan)

Add as a preferred
source on Google

The well-known game developer Riot Games recently suffered another widespread service disruption after failing to renew an expired digital certificate in time. The certificate in question expired on January 4, 2026, and once it lapsed, all HTTPS connections were rejected.

The immediate consequence was that the League of Legends client could no longer connect to the servers. Notably, this was not the first such incident. Back in January 2016, Riot Games similarly neglected to renew a certificate, and the replacement certificate issued at that time was set to expire in January 2026. A decade ago, Riot employees stated that the certificate would be automatically renewed and that similar issues would not recur. Ten years on, however, it appears the underlying certificate renewal problem remains unresolved.

The client certificate used by Riot is self-signed. In theory, this means Riot could issue a certificate valid for 20 years or even longer. However, longer validity periods increase the risk associated with potential private key compromise, which is why certificates are generally not issued for excessively long durations.

Forgetting to renew digital certificates is, of course, a long-standing and industry-wide problem. Google, Microsoft, and Apple have all experienced similar lapses. Apple, in fact, previously proposed shortening certificate validity periods to just 47 days—a move that ultimately gained industry support.

Under new rules set by the CA/Browser Forum, certificates issued by 2028 will have a maximum validity of only 47 days, excluding root and intermediate certificates. As a result, incidents caused by expired certificates and missed renewals are likely to become increasingly frequent.

Returning to the recent outage, a Riot Games employee reportedly became aware of the expired certificate only after seeing user complaints on Reddit. The employee then coordinated with the technical team to implement an emergency fix, and server connectivity was restored after several hours of downtime.

That said, some players may still encounter “unknown player” messages upon entering the game. Affected users are advised to update the client, restart the application, and ensure that their system clock is set to the correct time.

Related Posts:

  • Riot Games has been hacked: League of Legends and other game source codes stolen
  • League of Legends Fans Targeted: Beware the Lumma Stealer Lurking in Fake Ads!
  • DeepSeek’s Exposed Database Leaks Sensitive User Information
  • Windows Security Alert: Secure Boot Certificates Expiring in 2026, Update Now
  • CVE-2023-33975: RIOT-OS Code Execution Vulnerability
Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. SSL Certificate Validity Reduced to 47 Days After Apple Proposal
  2. HPE Completes $14B Juniper Networks Acquisition, Doubles Networking Business & Boosts AI Portfolio
  3. Cloudflare’s 1.1.1.1 DNS Suffers Global Outage Due to Internal Configuration Error
  4. The End of an Era: Popular CA Buypass to Halt Free TLS/SSL Certificates
  5. Cloudflare Outage Crashes the Internet: X, ChatGPT, and Major Websites Inaccessible
Tags: CA/Browser Forum cybersecurity Digital Trust https League of Legends LoL Login Fix Networking outage Riot Games SSL Certificate

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-0611CVSS 9.8
    Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain...
  • CVE-2026-7312CVSS 10.0
    CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from...
  • CVE-2026-7198CVSS 9.8
    CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before...
  • CVE-2026-47117CVSS 9.8
    OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII...
  • CVE-2026-42684CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2025-53209CVSS 9.8
    Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation....
  • CVE-2026-8206CVSS 9.8
    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for...
  • CVE-2026-25879CVSS 9.8
    Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0,...
  • CVE-2026-40965CVSS 10.0
    Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private...
  • CVE-2018-25427CVSS 9.8
    Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity © All rights reserved.