Vulnerability
Advisory/Mitigation
Exploitation Wave
FortiGate SSL VPN 2FA bypass still under abuse
Updated 02.01.2026 18:01
Case score 66
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 66
- Main story score
- 64
- Related evidence lift
- +2 / 20
- Contributing updates
- 1
- Context updates
- 1
Top contributors
- Vulnerability Base anchor on active exploitation of CVE-2020-12812 in FortiGate SSL VPN deployments. main
- Advisory Mitigation Provides remediation guidance for the same CVE and authentication path; useful context but no added support value. context
- Exploitation Wave Confirms ongoing in-the-wild abuse of the same FortiOS/FortiGate login bypass and adds limited support to the case. contributes
Members 3
First seen 25.12.2025 10:22
Latest activity 02.01.2026 18:01
Overview
**FortiGate SSL VPN** exploitation tied to **CVE-2020-12812** is still active against deployments that combine local users, **LDAP**, and **FortiToken** 2FA. Attackers can change the username case to bypass the second factor, and Fortinet says more than **10,000** firewalls remain exposed, including more than **1,300** IPs in the **United States**.
Fortinet's later advisory keeps the response focused on configuration hardening, disabling **username-case-sensitivity** or **username-sensitivity**, and resetting credentials where abuse is suspected.
Latest development Open development history FortiGate firewalls CVE-2020-12812 active exploitation wave The current phase is defined by **ongoing in-the-wild abuse** of **CVE-2020-12812** against **FortiGate firewalls** that expose **LDAP-linked** authentication flows. Systems with the vulnerable local-user and remote-authentication setup can still be logged into without the second factor when the username case is altered.
-
FortiGate SSL VPN active 2FA bypass (CVE-2020-12812)
Fortinet originally patched **CVE-2020-12812** in **July 2020** and recommended disabling **username-case-sensitivity** as a workaround for systems that could not be updated right away. The event reappeared in **January 2026** when Fortinet warned that attackers were still exploiting the flaw in vulnerable **FortiGate SSL VPN** configurations.
Attackers are still abusing **CVE-2020-12812** in **FortiGate SSL VPN** deployments that rely on **LDAP**-linked local users and **FortiToken** second-factor checks. The bypass works when a username's case is changed, letting a login succeed without the second factor in vulnerable configurations. An active exploitation wave tied to the same flaw shows that exposed appliances remain at risk even years after Fortinet's **July 2020** fix. Fortinet said more than **10,000** firewalls remain exposed online, including more than **1,300** IP addresses in the **United States**, even though it shipped fixes in **July 2020** and recommended disabling **username-case-sensitivity** for systems that could not be updated immediately.
Fortinet's later mitigation advisory for **CVE-2020-12812** warned that vulnerable **FortiOS SSL VPN** configurations can let admin or VPN users authenticate without **2FA** when username case handling and LDAP fallback align. The advisory told customers to disable **username-sensitivity** or remove the secondary **LDAP group** path so logins cannot fall through to the bypass condition. If there is evidence of successful abuse, Fortinet also advised impacted customers to contact support and reset all credentials.
Signals
Impact signals
Exploitation
CVEs/products
Remediation
Data exposure
Technical intelligence
Existing Case dataMember happenings
Vulnerability
FortiGate SSL VPN active 2FA bypass (CVE-2020-12812)
Exploitation
Active Exploitation
Exploit
Public Exploit
CVSS
9.8 Critical
Data Status
Exposed/Unsecured
1 more in details
Vulnerability
FortiGate SSL VPN active 2FA bypass (CVE-2020-12812)
Exploitation
Active Exploitation
Exploit
Public Exploit
CVSS
9.8 Critical
Data Status
Exposed/Unsecured
1 more in details
Exploitation Wave
FortiGate firewalls CVE-2020-12812 active exploitation wave
Exploitation
Active Exploitation
Patch
Patch Available
Exploitation Wave
FortiGate firewalls CVE-2020-12812 active exploitation wave
Exploitation
Active Exploitation
Patch
Patch Available
Advisory/Mitigation
FortiOS SSL VPN CVE-2020-12812 mitigation advisory
Exploitation
Active Exploitation
CVSS
5.2 Medium
Urgency
Immediate
Advisory/Mitigation
FortiOS SSL VPN CVE-2020-12812 mitigation advisory
Exploitation
Active Exploitation
CVSS
5.2 Medium
Urgency
Immediate