Cybercriminals are actively exploiting a vulnerability in Fortinet FortiGate firewalls (CVE-2020-12812) that allows them to bypass two-factor authentication (2FA) and gain unauthorized access to VPNs and administrative consoles. The flaw, originally patched in 2020, arises from a case-sensitivity mismatch between FortiGate's handling of usernames and that of LDAP directories, such as Active Directory. Attackers can exploit misconfigured environments where local FortiGate users with 2FA are also members of LDAP groups mapped to authentication policies, enabling them to log in using case-variant usernames and valid LDAP credentials, thereby bypassing 2FA entirely.
Fortinet has confirmed that successful exploitation can grant attackers VPN access or elevated privileges without requiring a second authentication factor. The company urges administrators to audit configurations, reset all credentials (including LDAP/AD binding accounts), and review logs for suspicious authentication patterns. Despite the availability of patches since 2020, unpatched or misconfigured devices remain at risk, and opportunistic attackers are actively targeting these systems in the wild.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
In response to the renewed exploitation, Fortinet and security outlets urged administrators to upgrade to patched FortiOS versions, audit authentication configurations, monitor logs, and disable username case sensitivity as a workaround where needed. The guidance emphasized that unpatched or misconfigured systems remain exposed.
Multiple December 2025 reports said attackers were actively exploiting the long-patched Fortinet vulnerability CVE-2020-12812 in the wild. The bug lets attackers bypass 2FA by abusing username case-sensitivity differences between FortiGate/FortiOS and LDAP in specific configurations.
Government agencies including the FBI, CISA, ACSC, and NCSC issued alerts warning that CVE-2020-12812 and related Fortinet vulnerabilities were being exploited. The alerts highlighted use by threat actors including Iran-linked groups and ransomware operators.
Fortinet addressed CVE-2020-12812 in July 2020. The flaw affected FortiOS SSL VPN and could allow two-factor authentication bypass in certain LDAP-linked configurations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
secpod.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.