logo

Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls

ID: d496fb9d-f6f1-5ea6-bfe2-d74ba7744eb3

STIX ID: report--d496fb9d-f6f1-5ea6-bfe2-d74ba7744eb3

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-25

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive summary:** Attackers are actively abusing Fortinet FortiGate CVE-2020-12812 (FG-IR-19-283) by exploiting a username case-sensitivity mismatch between FortiGate and LDAP to bypass 2FA and gain VPN or admin access; Fortinet documents observed probes and urges immediate patching, configuration changes (disable username case sensitivity or remove LDAP group fallbacks), credential resets, and log audits to detect compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.