A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
https://www.pingidentity.com/en/resources/downloads/pingid.html
https://docs.pingidentity.com/bundle/pingid/page/klc1641469599716.html