Vulnerability
Advisory/Mitigation
Exploitation Wave
FortiGate SSL VPN 2FA bypass still under abuse
Updated 02.01.2026 18:01
Case score 66
Score breakdown
- Total
- 66
- Lead score
- 64
- Support bonus
- +2 / 20
- Scoring support
- 1
- Context members
- 1
Top contributors
- Vulnerability Base anchor on active exploitation of CVE-2020-12812 in FortiGate SSL VPN deployments. base
- Advisory Mitigation Provides remediation guidance for the same CVE and authentication path; useful context but no added support value. context
- Exploitation Wave Confirms ongoing in-the-wild abuse of the same FortiOS/FortiGate login bypass and adds limited support to the case. support
Case score 66
Members 3
Latest activity 02.01.2026 18:01
Active exploitation
Public PoC/exploit reported
Patch/mitigation varies by member
CVSS: 9.8 Critical
Active exploitation
Public PoC/exploit reported
Patch/mitigation varies by member
CVSS: 9.8 Critical
Members 3
First seen 25.12.2025 10:22
Last seen 02.01.2026 18:01
Updated 02.01.2026 18:01
Overview
**FortiGate SSL VPN** exploitation tied to **CVE-2020-12812** is still active against deployments that combine local users, **LDAP**, and **FortiToken** 2FA. Attackers can change the username case to bypass the second factor, and Fortinet says more than **10,000** firewalls remain exposed, including more than **1,300** IPs in the **United States**.
Fortinet's later advisory keeps the response focused on configuration hardening, disabling **username-case-sensitivity** or **username-sensitivity**, and resetting credentials where abuse is suspected.
Attackers are still abusing **CVE-2020-12812** in **FortiGate SSL VPN** deployments that rely on **LDAP**-linked local users and **FortiToken** second-factor checks. The bypass works when a username's case is changed, letting a login succeed without the second factor in vulnerable configurations. An active exploitation wave tied to the same flaw shows that exposed appliances remain at risk even years after Fortinet's **July 2020** fix. Fortinet said more than **10,000** firewalls remain exposed online, including more than **1,300** IP addresses in the **United States**, even though it shipped fixes in **July 2020** and recommended disabling **username-case-sensitivity** for systems that could not be updated immediately.
Fortinet's later mitigation advisory for **CVE-2020-12812** warned that vulnerable **FortiOS SSL VPN** configurations can let admin or VPN users authenticate without **2FA** when username case handling and LDAP fallback align. The advisory told customers to disable **username-sensitivity** or remove the secondary **LDAP group** path so logins cannot fall through to the bypass condition. If there is evidence of successful abuse, Fortinet also advised impacted customers to contact support and reset all credentials.