FortiOS 7.0.17 release notes

synced 2026-08-02

FortiOS 7.0.17 is a maintenance and security release fixing four functional defects and six CVEs. The supplied notes also list 62 existing known issues and direct administrators to Fortinet's model-specific Upgrade Path Tool.

Official Fortinet release notes ↗

Security fixes

  • #1093598CVE-2024-50571

    CVE-2024-50571 fixed

    FortiOS 7.0.17 is no longer vulnerable.

  • #1100972CVE-2024-52965

    CVE-2024-52965 fixed

    FortiOS 7.0.17 is no longer vulnerable.

  • #1103505CVE-2024-55591

    CVE-2024-55591 fixed

    FortiOS 7.0.17 is no longer vulnerable.

  • #1108301CVE-2025-22254

    CVE-2025-22254 fixed

    FortiOS 7.0.17 is no longer vulnerable.

  • #1109252CVE-2025-25252

    CVE-2025-25252 fixed

    FortiOS 7.0.17 is no longer vulnerable.

  • #1112305CVE-2025-22258

    CVE-2025-22258 fixed

    FortiOS 7.0.17 is no longer vulnerable.

Upgrade notes

  • Use the model-specific Upgrade Path Tool

    Supported paths depend on the FortiGate model and current version. In Fortinet's Upgrade Path Tool, select FortiGate / FortiOS, the product model, current version, and target version, then click Go to obtain the supported sequence.

Resolved issues

  • #1110382

    GUI password login bypassed HTTPS PKI requirement

    Fixed an issue where an administrator could log in to the GUI over HTTPS with a password even when `admin-https-pki-required` was enabled.

  • #989677

    REST API JavaScript dependencies updated

    Updated JavaScript components to the latest Long Term Support version.

  • #935297

    AWS probe appeared in default SD-WAN checks

    Fixed `aws.amazon.com` being listed in the SD-WAN default health-check list.

  • #1101837

    Insufficient SSL VPN SAML session expiration

    Fixed insufficient session expiration in SSL VPN when using SAML authentication.

Known issues

  • #1117475

    SSL VPN SAML login fails with internal browser

    FortiClient cannot connect to FortiGate SSL VPN using SAML login when an internal browser is selected as the SAML authentication user agent.

  • #1117005

    IPsec NPU offload can cause post-upgrade CPU spikes

    On certain FortiGate models, CPU spikes and management-access problems can occur after upgrade when IPsec Phase 1 NPU offload is enabled during maintenance.

  • #843554

    GUI can alter the first IP service object's protocol

    Creating an IP-protocol firewall service in the GUI may silently modify the protocol number of the first IP-type service, potentially affecting policies such as those using `ALL` on some 6K and 7K platforms. Workaround: create the service in the CLI or place a non-IP service first, for example: `config firewall service custom`; `edit "unused"`; `set tcp-portrange 1`; `next`; `move "unused" before "ALL"`; `end`.

  • #912740

    FortiManager policies may split into separate sequence groups

    After upgrading a FortiManager-managed FortiGate to 7.0.13, unique `global-label` values may create separate sequence groups for each policy. Workaround: drag policies into the correct group or remove `global-label` from each member except the leading policy.

  • #951984

    Local-out DNAT may select the wrong route

    The best output route may not be found for local-out DNAT traffic.

  • #941521

    FortiView category filter fails in Japanese GUI

    The Category filter on Dashboard > FortiView Websites does not work in the Japanese GUI.

  • #440197

    FortiGuard override server status displays Unknown

    The System > FortiGuard page may show Unknown for a working AntiVirus and IPS update override server. This is display-only; the override continues to function.

  • #677806

    Global VDOM view misreports IPsec tunnel status

    With VDOM mode enabled, Network > Interfaces in Global view may show IPsec interfaces from non-management VDOMs as UP. The VDOM view is accurate.

  • #685431

    Large firewall policy lists load slowly

    Policy & Objects > Firewall Policy can take about 30 seconds or longer to load with more than 20,000 policies. Workaround: configure policies through the CLI.

  • #707589

    Certificate reference count and deletion result can be wrong

    System > Certificates may show an incorrect reference count and permit an attempted deletion of a referenced certificate. The deletion fails despite a success message; remove all references before deletion.

  • #708005

    Firefox cannot paste into SSL VPN SSH terminal

    Users cannot paste text into the SSL VPN web portal SSH terminal emulator in Firefox. Workaround: use Chrome, Edge, or Safari.

  • #755177

    GUI incorrectly rejects the 7.0.1-to-7.0.2 path

    The GUI displays an invalid-upgrade-path warning when upgrading firmware from 7.0.1 to 7.0.2.

  • #810225

    First administrator password change shows undefined

    An undefined error appears when an administrator password is changed for the first time on NP7 platforms.

  • #853352

    Internet Service Database pane cannot reach final entries

    The View/Edit Entries pane under Policy & Objects > Internet Service Database cannot scroll to the end when it contains more than 100,000 entries.

  • #881678

    GUI cannot edit very large prefix lists

    Editing a prefix list with many rules under Network > Routing Objects fails with an integer-range error. Workaround: edit the prefix list through the CLI.

  • #898902

    Two-factor toggle loads slowly with many VDOMs

    With more than 200 VDOMs, System > Administrators may take over one minute to load the Two-factor Authentication toggle. Other settings are unaffected. Workaround: configure `two-factor-authentication` under `config system admin` in the CLI.

  • #974988

    Valid account license can still trigger expiration notice

    The GUI may show a FortiManager Cloud expiration notification for an expired device-level license even when a valid account-level license exists. Functionality is unaffected.

  • #1102588

    High security level blocks graceful HA upgrade

    On FortiGate 12xG and 9xG devices, graceful upgrade of the secondary HA node fails at high security level. Workaround: disable HA and upgrade units separately, or temporarily lower the security level and restore it afterward.

  • #771857

    Hyperscale policies expose unsupported VIP options

    Hyperscale firewall policies do not support VIP features `srcfltr`, `srcintf-fltr`, `service`, `arp-reply`, `nat-source-vip`, or port forwarding, although these appear in the CLI or GUI for IPv4 and IPv6 VIP configuration.

  • #811109

    Selected hyperscale interfaces cannot join an LAG

    HA1, HA2, AUX1, and AUX2 interfaces cannot be added to an LAG on FortiGate 4200F, 4201F, 4400F, and 4401F.

  • #836976

    Changing hyperscale log processor may drop sessions

    Sessions may be dropped when dynamically changing a hyperscale policy's hardware log server `log-processor` from `hardware` to `host`. Make this change during quiet periods.

  • #838654

    Implicit-deny hit count omits hardware NAT46 and NAT64

    The implicit-deny policy hit count does not increment for hardware sessions carrying NAT46 or NAT64 traffic.

  • #842659

    IPv6 FTS address negation is incorrect

    `srcaddr-negate` and `dstaddr-negate` do not work correctly for IPv6 traffic with FTS.

  • #843132

    New hyperscale ACLs may be delayed

    ACL policies added while a hyperscale VDOM is processing traffic can take longer than expected to become effective; traffic intended to be blocked may be allowed during the transition.

  • #843197

    NPU session list omits policy-route data

    The NPU session list does not display policy-route information for traffic routed through a policy route on NPU-accelerated models.

  • #843266

    Hyperscale diagnostic lacks route and session counters

    A diagnostic command is unavailable for showing `hit_count` and `last_used` for policy routes and NPU sessions in a hyperscale VDOM.

  • #843305

    NPD policy-route parsing error appears at boot

    The console can report `PARSE SKIP ERROR=17 NPD ERR PBR ADDRESS` during system startup.

  • #844421

    IP pool diagnostic output is wrong for overload pools

    The `diagnose firewall ippool list` command does not produce correct output for overload-type IP pools.

  • #845269

    GUI disables CGN endpoint-independent filtering

    Editing a hyperscale policy with an overload CGN IP pool causes the GUI to disable `cgn-eif`, regardless of its previous state.

  • #846520

    NPD or LPMD can be terminated for low memory

    The out-of-memory killer may terminate NPD or LPMD after mixed-session traffic and HA failover.

  • #895951

    EIF NPU setup rate incorrectly reports zero

    `diagnose sys npu-session stat` incorrectly reports a `setup rate` of `0` for EIF sessions.

  • #941784

    FG-480xF hyperscale sessions do not synchronize

    Hardware session synchronization does not work on FG-480xF devices in hyperscale mode.

  • #986656

    HA primary reports zero NPU session state

    The HA primary's NPU session list can contain many sessions while NPU session state reports `0`.

  • #993343

    NAT46 fragment-header option can interrupt the kernel

    A kernel interruption can occur in a hyperscale VDOM when `set nat46-generate-ipv6-fragment-header` is enabled.

  • #1024902

    NPU session statistics miscount FTP sessions

    After FTP traffic passes, `npu-session stat` does not report the actual session count accurately.

  • #761754

    Down IPsec aggregate route remains active

    An IPsec aggregate static route is not marked inactive when its IPsec aggregate is down.

  • #945367

    ADVPN shortcuts do not inherit disabled source checking

    Disabling `src-check` reverse-path forwarding on the parent tunnel is not inherited by ADVPN shortcuts.

  • #850642

    Concurrent configuration changes can suppress traffic logs

    Traffic logs may not appear when numerous configuration changes occur simultaneously.

  • #1001497

    Invalid HTTP date can trigger conserve mode

    FortiGate may enter conserve mode when a missing or invalid HTTP date is posted through the web proxy.

  • #614691

    Large Security Fabric topology slows the GUI

    GUI performance is slow in a Fabric topology with more than 50 downstream devices.

  • #794703

    Security Rating checks return incorrect results

    The Rogue AP Detection and FortiCare Support checks in Security Rating reports may show incorrect results.

  • #862424

    Security Rating may cause conserve mode on large tables

    Running Security Rating reports on a FortiGate with more than 1,000 firewall policies, addresses, or other table entries may cause conserve mode.

  • #903922

    Large Fabric topology views load slowly

    Physical and logical Security Fabric topology views load slowly with many downstream FortiGates, FortiSwitches, FortiAPs, and endpoint traffic. This is a GUI-only issue and does not affect downstream operation.

  • #847664

    Hardware error message can appear after burn or reboot

    The console may display `mce: [Hardware Error]` after a fresh image burn or reboot.

  • #861962

    One-gigabit aggregate interface cannot pass traffic

    An 802.3ad aggregate configured for 1 Gbps may have an unlit port LED and pass no traffic. Affected platforms are 110xE, 220xE, 330xE, 340xE, and 360xE.

  • #934708

    CMDB server cannot acquire var_zone lock

    The cmdbsvr process may fail to secure the var_zone lock because another process holds it indefinitely.

  • #935158

    Missing GUI redirect file message appears after reboot

    The console may print `check_gui_redir_file: No such file or directory` after reboot.

  • #975496

    FortiGate 200F is slow between 1G and 10G interfaces

    Download and upload performance may be slow when traffic traverses from a 1G interface to a 10G interface on FortiGate 200F.

  • #1082256

    BIOS level 2 upgrade can fail integrity checking

    Upgrading from 7.0.15 to 7.0.16 with BIOS security level 2 may produce `System file integrity check failed!`.

  • #800935

    ESXi VLAN interface over LACP does not work

    An ESXi VLAN interface based on LACP is nonfunctional.

  • #1082304

    Selected VM platforms can encounter kernel upgrade errors

    ARM64 KVM, AWS, and OCI FortiGate VMs and VM64 OPC can encounter a kernel error while upgrading from 7.0.15 to 7.0.16. The OCI bare-metal kernel image is unsupported in 7.0.16 when upgrading from 7.0.13, 7.0.14, or 7.0.15.

  • #766126

    Video filter does not automatically show block page

    The block replacement page is not automatically pushed to replace video content when a video filter blocks it.

  • #814541

    Large FortiAP deployments load slowly in the GUI

    With more than 500 managed FortiAPs and 5,000 WiFi clients, the Managed FortiAPs page and FortiAP Status widget can take a long time to load. FortiAP operation is unaffected.

  • #1004338

    NP7 WiFi DHCP-relay traffic fails after restart

    After an upgrade or reboot on NP7 platforms, WiFi data cannot pass when the SSID VLAN interface uses DHCP Relay Server.

  • #819987

    ZTNA mapped drives fail after laptop reboot

    Mapped drives can become inaccessible after a laptop reboots when using a FortiGate ZTNA access proxy with FQDN destinations.

  • #848222

    ZTNA TCP forwarding fails with FQDN real server

    ZTNA TCP forwarding does not work when the real server uses an FQDN address type. Publicly resolvable FQDNs are not recommended because the internal DNS database zone may override them; after reboot, the private address may not take effect and the real server may not be found.