FortiOS 7.0.18 release notes
FortiOS 7.0.18 is a maintenance and security release that resolves 12 product defects and three stated CVEs. No new known issues are identified, but 65 issues from previous releases remain. Upgrade paths are model- and source-version-specific and must be checked with Fortinet's Upgrade Path Tool.
Official Fortinet release notes ↗Security fixes
- #1173156CVE-2025-25249
CVE-2025-25249 fixed
FortiOS 7.0.18 is no longer vulnerable to CVE-2025-25249. See the FortiGuard PSIRT portal for more information.
- #1177284CVE-2025-53844
CVE-2025-53844 fixed
FortiOS 7.0.18 is no longer vulnerable to CVE-2025-53844. See the FortiGuard PSIRT portal for more information.
- #1184468CVE-2025-59718
CVE-2025-59718 fixed
FortiOS 7.0.18 is no longer vulnerable to CVE-2025-59718. See the FortiGuard PSIRT portal for more information.
Upgrade notes
Use the Fortinet Upgrade Path Tool
Supported upgrade paths depend on the FortiGate model, current FortiOS version, and target version. In the Fortinet Document Library, open Tools & Resources > Upgrade Path Tool, choose FortiGate / FortiOS, select the model, current version, and target version, then click Go.
Resolved issues
- #931699
HA configuration restore failure fixed
An invalid value set for the dhcp-renew-time attribute no longer causes an error while restoring configuration in an HA cluster.
- #1016927
Custom IKE-port ESP processing fixed
The new kernel platform now processes UDP-encapsulated ESP packets when a custom ike-port is used.
- #996269
WAD corner-case crash fixed
A WAD crash in one of its functions under certain corner cases has been fixed.
- #1018780
Post-upgrade WAD memory issue fixed
A FortiGate memory-usage issue caused by the WAD process after an upgrade has been fixed.
- #1023127
WAD signal 11 crash fixed
A WAD signal 11 crash on FortiGate devices has been fixed.
- #1109152
SSL VPN web-mode Telnet and SSH loading fixed
SSL VPN web-mode Telnet and SSH pages no longer remain loading without presenting a login page.
- #1110901
SSL VPN web-mode SSH regression fixed
SSL VPN web-mode SSH now works after upgrading from the affected 7.0.16 release.
- #1031179
SSL VPN hterm service disruption fixed
SSH and Telnet service disruption caused by incorrectly removing hterm_all.js from the SSL VPN web portal has been fixed.
- #1196434
Unsigned SAML response handling fixed
SAML authentication issues have been fixed when LASSO_PROFILE_SIGNATURE_VERIFY_HINT_FORCE is set and the SAML response is unsigned.
Known issues
- #843554
GUI can silently alter an IP service protocol number
If the first firewall service object in CLI table order has protocol type IP, creating another IP service in the GUI may incorrectly modify the first object's protocol number. This can affect policies, including those using ALL on some 6K/7K platforms. Workaround: create the service in the CLI or place a non-IP service first, for example: `config firewall service custom`; `edit "unused"`; `set tcp-portrange 1`; `next`; `move "unused" before "ALL"`; `end`.
- #912740
FortiManager policy sequence grouping can split
After upgrading a FortiManager-managed FortiGate to 7.0.13, the Firewall Policy list may create separate sequence groups because global-label becomes unique for each policy. Workaround: drag policies into the correct GUI group, or remove global-label from each member except the leading policy.
- #951984
Local-out DNAT may select no best route
For local-out DNAT traffic, the best output route may not be found.
- #951135
FortiGate 6000/7000 graceful upgrade limitation
Graceful upgrade of a FortiGate 6000 or 7000 FGCP HA cluster is unsupported from FortiOS 7.0.12 to 7.2.5 or 7.2.6. Perform the upgrade in a maintenance window because traffic can be disrupted for up to 30 minutes. Disable `uninterruptible-upgrade` and perform a normal firmware upgrade; traffic remains unavailable until all management boards and FPCs, or FIMs and FPMs, are upgraded and both FortiGates restart.
- #963201
One-to-One NAT policy traffic conflict risk
Traffic-flow conflicts may occur when One-to-One is used as a NAT policy.
- #987672
DEI-marked fragments fail
Fragment packets with `DEI == 1` do not work on FortiGate 6000/7000 platforms.
- #941521
Japanese FortiView category filter fails
The Category filter on Dashboard > FortiView Websites does not work in the Japanese GUI.
- #440197
FortiGuard override server status displays Unknown
System > FortiGuard may show Unknown for a working override FortiGuard server used for AntiVirus and IPS updates. This is display-only; override operation is unaffected.
- #677806
Global interface view misreports IPsec tunnel status
With VDOM mode enabled, Network > Interfaces in Global view may show non-management VDOM IPsec tunnel interfaces as UP. The VDOM view reports the correct status.
- #685431
Large firewall policy lists load slowly
Policy & Objects > Firewall Policy can take about 30 seconds or more to load with over 20,000 policies. Workaround: configure policies through the CLI.
- #707589
Certificate reference count and deletion status can be wrong
System > Certificates may show an incorrect reference count and allow an attempted deletion of a referenced certificate. The deletion fails even though the GUI reports success; deletion works after all references are removed.
- #708005
Firefox cannot paste into SSL VPN SSH terminal
Users cannot paste text into the SSL VPN web portal SSH terminal emulator in Firefox. Workaround: use Chrome, Edge, or Safari.
- #755177
GUI flags valid 7.0.1-to-7.0.2 upgrade path
When upgrading from 7.0.1 to 7.0.2, the GUI incorrectly warns that the upgrade path is invalid.
- #810225
NP7 first password change reports undefined error
An undefined error appears when changing an administrator password for the first time on NP7 platforms.
- #853352
Large Internet Service Database pane cannot scroll fully
The View/Edit Entries pane under Policy & Objects > Internet Service Database cannot scroll to the end when it contains over 100,000 entries.
- #881678
Large prefix lists cannot be edited in GUI
Editing a prefix list with many rules under Network > Routing Objects can fail with an integer-range error. Workaround: edit the prefix list through the CLI.
- #898902
Two-factor toggle loads slowly with many VDOMs
With more than 200 VDOMs, System > Administrators may take over one minute to load the Two-factor Authentication toggle. Other settings are unaffected. Workaround: configure `two-factor-authentication` under `config system admin` in the CLI.
- #974988
Valid FortiManager Cloud license can show expired
The GUI may report an expired device-level FortiManager Cloud license even when a valid account-level license exists. Functionality is unaffected.
- #1102588
High security level blocks secondary graceful upgrade
On FortiGate 12xG and 9xG series devices, graceful upgrade of the secondary HA node fails when security level is high. Workaround: disable HA and upgrade units separately, or lower the security level for the upgrade and restore it afterward.
- #771857
Hyperscale policies expose unsupported VIP features
Hyperscale firewall policies do not support VIP features srcfltr, srcintf-fltr, service, arp-reply, nat-source-vip, or portforwarding, although these options appear in the CLI or GUI for IPv4 and IPv6 VIPs in a hyperscale VDOM.
- #811109
Selected high-end interfaces cannot join an LAG
HA1, HA2, AUX1, and AUX2 interfaces on FortiGate 4200F, 4201F, 4400F, and 4401F cannot be added to an LAG.
- #836976
Changing hyperscale log processor can drop sessions
Sessions using hyperscale policies with hardware logging may be dropped when `log-processor` is changed dynamically from `hardware` to `host`. Change the setting during a quiet period.
- #838654
Implicit-deny hit count fails for NAT46 and NAT64
The implicit-deny policy hit count does not increment for hardware sessions carrying NAT46 or NAT64 traffic.
- #842659
IPv6 FTS address negation fails
`srcaddr-negate` and `dstaddr-negate` do not work correctly for IPv6 traffic with FTS.
- #843132
Hyperscale ACL enforcement can be delayed
New ACL policies on a busy hyperscale VDOM may take longer than expected to become effective. During the transition, traffic that should be blocked may be allowed.
- #843197
NPU session list omits policy-route data
The npu-session list does not display policy-route information when accelerated traffic uses a policy route.
- #843266
Hyperscale route diagnostics lack usage data
A diagnostic command to show hit_count and last_used for policy routes and NPU sessions is unavailable in a hyperscale VDOM.
- #843305
Hyperscale boot logs PBR parse error
The console can display `PARSE SKIP ERROR=17 NPD ERR PBR ADDRESS` during system startup.
- #844421
IP pool diagnostic output is incorrect
The `diagnose firewall ippool list` command does not show correct output for overload-type IP pools.
- #845269
GUI disables CGN endpoint-independent filtering
Editing a hyperscale policy using an overload CGN IP pool causes the GUI to disable `cgn-eif` regardless of its prior state.
- #846520
NPD or LPMD can be killed after HA failover
The out-of-memory killer may terminate the NPD or LPMD process after mixed-session traffic and an HA failover.
- #895951
EIF session setup rate reports zero
The `diagnose sys npu-session stat` command incorrectly reports a setup rate of 0 for EIF sessions.
- #941784
FG-480xF hyperscale hardware sessions do not synchronize
Hardware session synchronization does not work on FG-480xF devices in hyperscale mode.
- #986656
HA primary reports zero NPU session state
The HA primary can show many entries in the npu-session list while npu-session state reports 0.
- #993343
NAT46 fragment-header option can interrupt kernel
A kernel interruption can occur in a hyperscale VDOM when `set nat46-generate-ipv6-fragment-header` is enabled.
- #1024902
NPU session statistics undercount after FTP traffic
After FTP traffic passes, `npu-session stat` does not report the accurate number of sessions.
- #761754
Down IPsec aggregate route remains active
An IPsec aggregate static route is not marked inactive when the IPsec aggregate is down.
- #945367
ADVPN shortcuts do not inherit disabled RPF
Disabling `src-check` on the parent tunnel is not inherited by ADVPN shortcuts.
- #850642
Traffic logs can disappear during configuration bursts
Traffic logs may not be generated for firewall traffic when numerous configuration changes occur simultaneously.
- #1001497
Invalid HTTP date can trigger conserve mode
FortiGate may enter conserve mode when a non-date or invalid HTTP date is posted through the web proxy.
- #1117475
Internal-browser SAML SSL VPN connection fails
FortiClient cannot connect to FortiGate SSL VPN with SAML when an internal browser is used as the SAML user-authentication agent.
- #614691
Large Security Fabric topology is slow
GUI performance is slow in a Fabric topology with over 50 downstream devices.
- #794703
Security Rating checks report incorrect results
Security Rating reports show incorrect results for Rogue AP Detection and FortiCare Support checks.
- #862424
Security Rating can cause conserve mode
On FortiGates with tables exceeding 1,000 firewall policies, addresses, or other entries, Security Rating reports may cause conserve mode.
- #903922
Large Fabric topology views load slowly
Security Fabric physical and logical topology views are slow with many downstream FortiGates, FortiSwitches, FortiAPs, and endpoint traffic. This is GUI-only and does not affect downstream operation.
- #847664
Console can report machine-check hardware error
The console may display `mce: [Hardware Error]` after a fresh image burn or reboot.
- #861962
One-gigabit aggregate can lose LED and traffic
An 802.3ad aggregate configured at 1 Gbps can have an unlit port LED and pass no traffic on 110xE, 220xE, 330xE, 340xE, and 360xE platforms.
- #934708
cmdbsvr can be blocked from var_zone lock
cmdbsvr may be unable to secure the var_zone lock because another process holds it indefinitely.
- #935158
Console reports missing GUI redirect file
After reboot, the console may print `check_gui_redir_file: No such file or directory`.
- #975496
FortiGate 200F has slow 1G-to-10G throughput
FortiGate 200F can experience slow uploads and downloads for traffic traversing from a 1G interface to a 10G interface.
- #1117005
IPsec NPU offload can cause CPU and management issues
Certain FortiGate models can experience CPU spikes and management-access problems after an upgrade when IPsec Phase 1 NPU offload is enabled during maintenance.
- #1082256
BIOS security level 2 upgrade reports integrity failure
Upgrading from FortiOS 7.0.15 to 7.0.16 with BIOS security level 2 may report `System file integrity check failed!`.
- #800935
ESXi VLAN over LACP does not work
An ESXi VLAN interface based on LACP does not function.
- #1082304
Selected FortiGate VMs can hit kernel error during upgrade
ARM64 KVM, AWS, and OCI FortiGate VMs and VM64 OPC may encounter a kernel error when upgrading from 7.0.15 to 7.0.16. The OCI bare-metal kernel image is unsupported in 7.0.16 when upgrading from 7.0.13, 7.0.14, or 7.0.15.
- #766126
Video filter block page is not inserted automatically
The block replacement page is not automatically pushed to replace video content when a video filter blocks it.
- #814541
Large FortiAP deployments load slowly in GUI
With over 500 managed FortiAPs and over 5,000 WiFi clients, the Managed FortiAPs page and FortiAP Status widget can load slowly. FortiAP operation is unaffected.
- #1004338
NP7 SSID DHCP relay traffic fails after restart
After an upgrade or reboot on NP7 platforms, WiFi data may not pass when the SSID VLAN interface uses DHCP Relay Server.
- #819987
ZTNA mapped drives fail after laptop reboot
Mapped drives become inaccessible after a laptop reboots when FortiGate ZTNA access proxy uses FQDN destinations.
- #848222
ZTNA TCP forwarding fails with FQDN real server
ZTNA TCP forwarding does not work when the real server uses an FQDN address type. Publicly resolving FQDNs are not recommended because the internal DNS database zone can override resolution; after reboot, the private address may not take effect and the real server may not be found.
Special notices
No new known issues identified
Fortinet states that no new issues have currently been identified in FortiOS 7.0.18; all listed known issues originated in previous FortiOS versions and remain open in 7.0.18.