logo

10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability

ID: fad68822-7066-55c1-8077-3b8c453eb2e8

STIX ID: report--fad68822-7066-55c1-8077-3b8c453eb2e8

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Over 10,000 FortiGate firewalls remain vulnerable to CVE-2020-12812, an MFA bypass in FortiOS SSL VPN portals caused by case-sensitivity mismatches between local usernames and LDAP; attackers can bypass second-factor authentication by altering username case. Fortinet confirmed active abuse in late 2025, Shadowserver reports widespread exposure, and Fortinet urges upgrades to patched FortiOS versions and configuration checks to mitigate lateral movement and ransomware risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.