A session token read out of appliance memory bypasses the second factor entirely, because authentication already happened.
A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.
Six days between patch and intrusion. Faster than most manage, and longer than the window now exists.
A stolen session token arrives after authentication. Multi-factor is not bypassed — it is never consulted.