Vulnerability
Advisory/Mitigation
Exploitation Wave
FortiGate SSL VPN 2FA bypass still under abuse
Updated 02.01.2026 18:01
Case score 66
Score breakdown
- Total
- 66
- Lead score
- 64
- Support bonus
- +2 / 20
- Scoring support
- 1
- Context members
- 1
Top contributors
- Vulnerability Base anchor on active exploitation of CVE-2020-12812 in FortiGate SSL VPN deployments. base
- Advisory Mitigation Provides remediation guidance for the same CVE and authentication path; useful context but no added support value. context
- Exploitation Wave Confirms ongoing in-the-wild abuse of the same FortiOS/FortiGate login bypass and adds limited support to the case. support
Case score 66
Members 3
Latest activity 02.01.2026 18:01
Active exploitation
Public PoC/exploit reported
Patch status varies by member
CVSS: 9.8 Critical
Members 3
First seen 25.12.2025 10:22
Last seen 02.01.2026 18:01
Updated 02.01.2026 18:01
Overview
**FortiGate SSL VPN** exploitation tied to **CVE-2020-12812** is still active against deployments that combine local users, **LDAP**, and **FortiToken** 2FA. Attackers can change the username case to bypass the second factor, and Fortinet says more than **10,000** firewalls remain exposed, including more than **1,300** IPs in the **United States**.
Fortinet's later advisory keeps the response focused on configuration hardening, disabling **username-case-sensitivity** or **username-sensitivity**, and resetting credentials where abuse is suspected.
Attackers are still abusing **CVE-2020-12812** in **FortiGate SSL VPN** deployments that rely on **LDAP**-linked local users and **FortiToken** second-factor checks. The bypass works when a username's case is changed, letting a login succeed without the second factor in vulnerable configurations. An active exploitation wave tied to the same flaw shows that exposed appliances remain at risk even years after Fortinet's **July 2020** fix. Fortinet said more than **10,000** firewalls remain exposed online, including more than **1,300** IP addresses in the **United States**, even though it shipped fixes in **July 2020** and recommended disabling **username-case-sensitivity** for systems that could not be updated immediately.
Fortinet's later mitigation advisory for **CVE-2020-12812** warned that vulnerable **FortiOS SSL VPN** configurations can let admin or VPN users authenticate without **2FA** when username case handling and LDAP fallback align. The advisory told customers to disable **username-sensitivity** or remove the secondary **LDAP group** path so logins cannot fall through to the bypass condition. If there is evidence of successful abuse, Fortinet also advised impacted customers to contact support and reset all credentials.
Signals
8 derivedExploitation
Exploitation
Active exploitation
CVSS
Exploit
Public PoC/exploit reported
CVEs/products
CVE
Victims/regions
Victim region
United States
Remediation
Urgency
Immediate
Remediation
Data exposure
Leak status
Exposed/Unsecured
Member happenings
3 related
Vulnerability
FortiGate SSL VPN active 2FA bypass (CVE-2020-12812)
Exploitation
Active Exploitation
Exploit
Public Exploit
CVSS
9.8 Critical
Data Status
Exposed/Unsecured
+1
Vulnerability
FortiGate SSL VPN active 2FA bypass (CVE-2020-12812)
Exploitation
Active Exploitation
Exploit
Public Exploit
CVSS
9.8 Critical
Data Status
Exposed/Unsecured
+1
Exploitation Wave
FortiGate firewalls CVE-2020-12812 active exploitation wave
Exploitation
Active Exploitation
Patch
Patch Available
Exploitation Wave
FortiGate firewalls CVE-2020-12812 active exploitation wave
Exploitation
Active Exploitation
Patch
Patch Available
Advisory/Mitigation
FortiOS SSL VPN CVE-2020-12812 mitigation advisory
Exploitation
Active Exploitation
CVSS
5.2 Medium
Urgency
Immediate
Advisory/Mitigation
FortiOS SSL VPN CVE-2020-12812 mitigation advisory
Exploitation
Active Exploitation
CVSS
5.2 Medium
Urgency
Immediate