logo

Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks

ID: 425d94ce-cf2e-561e-b46d-b1fb6a510773

STIX ID: report--425d94ce-cf2e-561e-b46d-b1fb6a510773

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-12-29

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Fortinet warns that CVE-2020-12812, an improper authentication flaw in FortiGate SSL VPNs, is being actively exploited to bypass FortiToken two-factor authentication by changing username case; patches and mitigation guidance were released in July 2020. Recent activity includes attacks against LDAP-configured appliances, involvement of state-backed actors and ransomware misuse, and advisories from FBI/CISA with CISA adding the CVE to its known exploited vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.