Skip to content

WARNING: Hackers Actively Exploit Three-Year

Linkedin • December 26, 2025

Fortinet has warned customers that a years-old security vulnerability affecting its FortiOS SSL VPN software is being actively exploited in real-world attacks, renewing concerns the persistent risk posed by unpatched or misconfigured perimeter security devices.

In an advisory released on December 24, 2025, the network security vendor said it has observed “recent abuse” of CVE-2020-12812, an authentication flaw first disclosed nearly five years ago. The vulnerability allows attackers to bypass two-factor authentication (2FA) under certain configuration scenarios, potentially enabling unauthorized access to administrative interfaces and virtual private network (VPN) services.

Read the advisory HERE

CVE-2020-12812 is classified as an improper authentication vulnerability in FortiOS SSL VPN, carrying a CVSS score of 5.2. FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

While not considered critical on paper, the issue has proven highly attractive to threat actors due to its ability to undermine a key security control: multi-factor authentication.

According to Fortinet, the flaw arises from inconsistent handling of username case sensitivity between FortiGate devices and external directory services such as LDAP. FortiGate treats usernames as case-sensitive, while most LDAP directories do not. This discrepancy can be exploited when 2FA is enabled for local users that authenticate against a remote directory.

“If the case of the username does not exactly match the locally defined user, the FortiGate may fail to apply the local authentication policy and instead fall back to LDAP authentication,” Fortinet explained. In such cases, users may be authenticated successfully without being prompted for the second factor.

The company first documented the issue in July 2020, noting that it occurs when:

Two-factor authentication is enabled for a local user on the FortiGate device. That local user references a remote authentication method, such as LDAP. The same user belongs to one or more LDAP groups configured on the FortiGate and used in authentication policies for administrative access, SSL VPN, or IPsec VPN.

Under these conditions, a user who logs in with a differently capitalized version of their username—for example “JSmith” instead of “jsmith”—may bypass the local 2FA requirement entirely.

Fortinet said it has now confirmed that multiple threat actors are actively exploiting this behavior in the wild. While the company did not disclose details specific campaigns, victim organizations, or the success rate of the attacks, the warning underscores a broader trend: attackers continue to target known but insufficiently mitigated vulnerabilities in edge devices.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has previously highlighted CVE-2020-12812 as one of several vulnerabilities abused in attacks against perimeter network devices. The flaw was included in government assessments of exploitation activity observed during 2021, alongside other Fortinet, Pulse Secure, and Citrix vulnerabilities that were widely leveraged for initial access.

Security researchers have repeatedly warned that VPN appliances and firewalls remain prime targets for attackers, particularly ransomware operators and state-aligned groups, because they often provide direct access to internal networks and are frequently exposed to the internet.

Fortinet addressed the vulnerability in July 2020 with the release of FortiOS versions 6.0.10, 6.2.4, and 6.4.1. Despite the availability of fixes for several years, the company’s latest advisory suggests that some organizations either remain on vulnerable versions or have configurations that still allow the bypass to occur.

For organizations unable to upgrade immediately, Fortinet recommends configuration changes to mitigate the issue. On older FortiOS versions, administrators can disable case-sensitive username handling using the command:

For customers running FortiOS 6.0.13, 6.2.10, 6.4.7, 7.0.1, or later, the equivalent mitigation is:

With this setting disabled, FortiGate treats all variations of a username—such as “jsmith,” “JSmith,” or “JSMITH”—as identical, preventing the authentication logic from falling back to LDAP in a way that bypasses 2FA.

As an additional defensive measure, Fortinet advises customers to review their authentication policies and remove secondary LDAP groups if they are not strictly required. Eliminating unnecessary authentication paths can prevent attackers from exploiting misconfigurations altogether.

The resurgence of CVE-2020-12812 highlights a persistent challenge in enterprise cybersecurity: legacy vulnerabilities continue to pose risks long after patches are released. According to industry analysts, attackers frequently scan for older flaws precisely because many organizations delay upgrades due to operational complexity, compatibility concerns, or lack of visibility into exposed assets.

“This is another reminder that multi-factor authentication is only as strong as its implementation,” said several security experts in prior analyses of similar VPN flaws. “Configuration errors and edge-case behaviors can quietly negate protections organizations assume are in place.”

Fortinet has urged customers to investigate any signs that administrative or VPN users may have authenticated without 2FA and to reset all credentials if suspicious activity is discovered. Impacted customers are also encouraged to Fortinet support for further guidance.

As attackers continue to focus on perimeter infrastructure, security agencies and vendors alike stress the importance of timely patching, regular configuration audits, and continuous monitoring of authentication logs—especially for systems that sit at the gateway between the internet and internal corporate networks.

Extracted Entities

Companies (1)

Platforms (2)