I work for a SI Partner and I am noticing in multiple customer orgs since Spring 22, the same org may send the same user the same verification code by email, on different login attempts even hours or days apart. I had never seen this before Spring 22. Is there some weird bug recently introduced? ATTN: @Ian Glazer
OK, this just happened to me and I figured out why and how to workaround. In my scenario I have logged in to this org regularly from my home office which has had the Same (white listed) IP address forever. Today I'm logging in from a different location/IP Address and so MFA kicks in. Fine, here's your code...won't log me in. So round and round we go. Finally, I try logging in from a different Chrome profile and all works fine.
Conclusion: Browser cookies/caching is somehow causing the glitch (likely some well intentioned security measure to prevent hacking etc.). Workaround could have also been an incognito window or a different browser entirely. Once MFA was satisfied I could login again from original Chrome persona and all is good.