10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability
Over 10,000 Fortinet firewalls globally remain susceptible to CVE-2020-12812, a multi-factor authentication (MFA) bypass vulnerability identified over five and a half years ago.
Over 10,000 Fortinet firewalls globally remain susceptible to CVE-2020-12812, a multi-factor authentication (MFA) bypass vulnerability identified over five and a half years ago.
This vulnerability was recently included in Shadowserver's daily Vulnerable HTTP Report, emphasizing its ongoing exposure and active exploitation, as confirmed by Fortinet in late 2025.
CVE-2020-12812 originates from improper authentication within FortiOS SSL VPN portals, affecting versions 6.4.0, 6.2.0 through 6.2.3, and 6.0.9 and earlier. Attackers can bypass the second authentication factor by altering the case of a legitimate username during login.
This issue arises due to case sensitivity mismatches: FortiGate treats local usernames as case-sensitive, while LDAP servers, such as Active Directory , often disregard case, allowing authentication via group membership without MFA prompting.
The flaw holds a CVSS v3.1 base score of 7.5 (High), with potential impacts on confidentiality, integrity, and availability. It was included in CISA's Known Exploited Vulnerabilities catalog in 2021 following its use by ransomware actors.
In December 2025, Fortinet released a PSIRT advisory (FG-IR-19-283 update) addressing the vulnerability's recent exploitation in specific configurations: local FortiGate users with MFA enabled, linked to LDAP, and belonging to LDAP groups mapped to authentication policies for SSL VPN, IPsec , or admin access. Fortinet advises immediate checks and patches to prevent unauthorized network access.
Shadowserver's scans confirm the flaw's persistence, identifying vulnerable HTTP services on exposed ports.
Attackers can bypass the second authentication factor by altering the case of a legitimate username during login.
Shadowserver's dashboard indicates over 10,000 vulnerable instances as of early January 2026. The United States has the highest number of exposed firewalls at 1.3K, followed by Thailand (909), Taiwan (728), Japan (462), and China (462).
Top Countries Vulnerable Count
United States 1.3K
Thailand 909
Taiwan 728
Japan 462
China 462
Fortinet advises upgrading to fixed FortiOS versions (6.0.10+, 6.2.4+, 6.4.1+) and verifying configurations to prevent hybrid local-LDAP MFA setups. Additional recommendations include disabling unnecessary SSL VPN exposure, enforcing least privilege, and monitoring logs for case-variant login attempts. Organizations should subscribe to Shadowserver reports for tailored alerts and conduct Vulnerable HTTP scans promptly.
This issue highlights the risks associated with legacy vulnerabilities in enterprise firewalls, which can facilitate ransomware attacks or lateral movement within compromised networks.
Based on reporting by Cyber Security News.
