Story perspectives
Fortinet Warns of Exploited 5-Year-Old VPN Vulnerability
12/26/2025
36 5
1 of 1
Story summary
- Fortinet, Inc., reported active exploitation of a five-year-old vulnerability in FortiOS SSL VPN, tracked as CVE-2020-12812.
- Attackers bypass two-factor authentication by changing usernames' case; exploitation requires LDAP (Light Directory Access Protocol)-linked 2FA.
- Fortinet released updates in July 2020 to address the issue.
- The vulnerability has been exploited by actors, including the Hive group.
- Organizations with affected versions should disable username case sensitivity, and Fortinet advises credential resets if unauthorized access occurs.
