10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability
Over 10,000 Fortinet firewalls worldwide remain vulnerable to CVE-2020-12812, a multi-factor authentication (MFA) bypass flaw disclosed over five and a half years ago. Shadowserver recently added the issue to its daily Vulnerable HTTP Report, highlighting persistent exposure amid active exploitation confirmed by Fortinet in late 2025. Shadowserver’s scans confirm the flaw’s persistence, scanning for vulnerable HTTP services on exposed ports. Shadowserver’s dashboard reveals over 10,000 vulnerable instances as of early January 2026. The United States dominates with 1.3K exposed firewalls, followed by Thailand (909), Taiwan (728), Japan (462), and China (462).









