FortiOS 7.0.19 release notes

synced 2026-07-31

FortiOS 7.0.19 is a security-focused release that fixes CVE-2026-24858. Fortinet lists no new known issues, but 62 issues from earlier releases remain. Upgrade paths are model- and source-version-specific and must be checked with Fortinet's Upgrade Path Tool.

Official Fortinet release notes ↗

Security fixes

  • #1246654CVE-2026-24858

    CVE-2026-24858 fixed

    FortiOS 7.0.19 is no longer vulnerable to CVE-2026-24858. Fortinet directs users to https://fortiguard.com/psirt for additional information.

Upgrade notes

  • Use Fortinet Upgrade Path Tool before upgrading

    Supported upgrade paths depend on the FortiGate model, currently installed FortiOS version, and target version. In the Fortinet Document Library, open Tools & Resources > Upgrade Path Tool, select FortiGate / FortiOS, choose the model, current version, and target version, then select Go. Tool: https://docs.fortinet.com/upgrade-tool/.

Known issues

  • No new known issues in 7.0.19

    Fortinet states that no new issues have been identified specifically in version 7.0.19; the remaining known issues originated in previous FortiOS versions.

  • #843554

    GUI can silently alter an IP-type firewall service

    If the first firewall service object in CLI table order has protocol type IP, creating another IP-type service in the GUI may incorrectly change the first object's protocol number. This can affect policies using that service, including the ALL service on some 6000/7000 platforms. Workaround: create the service through the CLI or move a non-IP service before it, for example: `config firewall service custom edit "unused" set tcp-portrange 1 next move "unused" before "ALL" end`.

  • #912740

    FortiManager-managed policies may split into separate groups

    After upgrade to 7.0.13, a FortiManager-managed FortiGate may show separate sequence groups because each policy receives a unique `global-label`. Workaround: drag policies into the correct sequence group in the GUI, or remove `global-label` from each member except the leading policy.

  • #951984

    Local-out DNAT may select no best output route

    The best output route may not be found for local-out DNAT traffic.

  • #951135

    Graceful 6000/7000 HA upgrade path is unsupported

    Graceful upgrade of a FortiGate 6000/7000 FGCP HA cluster from 7.0.12 to 7.2.5 or 7.2.6 is unsupported. Use a maintenance window because traffic can be disrupted for up to 30 minutes. Disable `uninterruptible-upgrade` and perform a normal firmware upgrade; traffic remains unavailable until all management boards and FPCs, or FIMs and FPMs, are upgraded and both FortiGates restart.

  • #963201

    One-to-One NAT policy can create traffic-flow conflicts

    There is a traffic-flow conflict risk when One-to-One is used as a NAT policy.

  • #987672

    DEI-marked fragments do not work on 6000/7000

    Fragment packets with `DEI == 1` do not work on the FortiGate 6000/7000 platform.

  • #941521

    FortiView category filter fails in Japanese GUI

    The Category filter on Dashboard > FortiView Websites does not work when using the Japanese GUI.

  • #440197

    Working FortiGuard override server displays Unknown

    On System > FortiGuard, the override server for AntiVirus & IPS Updates may display Unknown even when working. This is display-only and does not affect override operation.

  • #677806

    Global interface view misreports IPsec tunnel status

    With VDOM mode enabled, Network > Interfaces in Global view may show IPsec tunnel interfaces from non-management VDOMs as UP incorrectly. The VDOM view reports the correct state.

  • #685431

    Large firewall policy lists load slowly

    Policy & Objects > Firewall Policy can require about 30 seconds or longer to load with more than 20,000 policies. Workaround: configure policies through the CLI.

  • #707589

    Certificate reference count and deletion status can be wrong

    System > Certificates can show an incorrect reference count and permit an attempted deletion of a referenced certificate. Deletion fails despite a success message; remove all references before deleting.

  • #708005

    Firefox cannot paste into SSL VPN SSH terminal

    Users cannot paste text into the SSL VPN web portal SSH terminal emulator in Firefox. Workaround: use Chrome, Edge, or Safari.

  • #755177

    GUI warns incorrectly about 7.0.1-to-7.0.2 path

    When upgrading from 7.0.1 to 7.0.2, the GUI can incorrectly say that the upgrade path is invalid.

  • #810225

    First administrator password change shows undefined error

    An undefined error appears when an administrator password is changed for the first time on NP7 platforms.

  • #853352

    Internet Service Database pane cannot reach final entries

    The View/Edit Entries pane under Policy & Objects > Internet Service Database cannot scroll to the end when it contains more than 100,000 entries.

  • #881678

    GUI cannot edit very large prefix lists

    Editing a prefix list with many rules under Network > Routing Objects fails with 'The integer value is not within valid range'. Workaround: edit the prefix list through the CLI.

  • #898902

    Two-factor toggle loads slowly with many VDOMs

    With more than 200 VDOMs, System > Administrators can take over one minute to load the Two-factor Authentication toggle. Other settings are unaffected. Workaround: configure `two-factor-authentication` under `config system admin` in the CLI.

  • #974988

    GUI may show an incorrect FortiManager Cloud expiry

    The GUI may report an expired device-level FortiManager Cloud license even when the account-level license remains valid. Functionality is unaffected.

  • #1102588

    High security level blocks graceful secondary-node upgrade

    On FortiGate 12xG and 9xG devices, graceful upgrade of the secondary HA node fails when security level is high. Workaround: disable HA and upgrade units separately, or lower the security level, upgrade, and restore it to high.

  • #771857

    Hyperscale policies expose unsupported VIP options

    Hyperscale firewall policies do not support VIP features `srcfltr`, `srcintf-fltr`, `service`, `arp-reply`, `nat-source-vip`, and `portforwarding`, although they remain visible in the CLI or GUI for IPv4 and IPv6 VIPs in a hyperscale VDOM.

  • #811109

    Selected hyperscale platform ports cannot join an LAG

    HA1, HA2, AUX1, and AUX2 interfaces cannot be added to an LAG on FortiGate 4200F, 4201F, 4400F, and 4401F.

  • #836976

    Changing hyperscale log processor can drop sessions

    Sessions may be dropped when dynamically changing `log-processor` from `hardware` to `host` for a hardware log server used by a hyperscale policy. Make this change during a quiet period.

  • #838654

    Implicit-deny hit count fails for NAT46 and NAT64

    The implicit-deny policy hit count does not increment for hardware sessions involving NAT46 or NAT64 traffic.

  • #842659

    IPv6 FTS address negation is unreliable

    `srcaddr-negate` and `dstaddr-negate` do not work correctly for IPv6 traffic with FTS.

  • #843132

    New hyperscale ACLs can take effect late

    ACL policies added to a traffic-processing hyperscale VDOM may take longer than expected to become effective. During the transition, traffic intended to be blocked may be allowed.

  • #843197

    NPU session list omits policy-route data

    The NPU session list does not show policy-route information when accelerated traffic is routed through a policy route.

  • #843266

    Hyperscale diagnostic data is unavailable

    A diagnostic command is not available to show `hit_count` and `last_used` for policy routes and NPU sessions in a hyperscale VDOM.

  • #843305

    Hyperscale boot emits PBR parse error

    The console can log `PARSE SKIP ERROR=17 NPD ERR PBR ADDRESS` during system startup.

  • #844421

    IP pool diagnostic output is incorrect

    `diagnose firewall ippool list` does not produce correct output for overload-type IP pools.

  • #845269

    GUI disables CGN endpoint-independent filtering

    Editing a hyperscale policy with an overload CGN IP pool in the GUI disables `cgn-eif`, regardless of its previous state.

  • #846520

    NPD or LPMD can be killed after failover

    The out-of-memory killer may terminate NPD or LPMD after mixed-session traffic and an HA failover.

  • #895951

    EIF session setup rate displays zero

    `diagnose sys npu-session stat` incorrectly reports a `setup rate` of `0` for EIF sessions.

  • #941784

    Hyperscale hardware sessions fail to synchronize

    Hardware-session synchronization does not work on FG-480xF devices in hyperscale mode.

  • #986656

    Primary HA NPU session state reports zero

    On the HA primary unit, the NPU session list may contain many sessions while NPU session state reports `0`.

  • #993343

    NAT46 fragment-header setting can interrupt kernel

    In a hyperscale VDOM, the kernel can encounter an interruption when `set nat46-generate-ipv6-fragment-header` is enabled.

  • #1024902

    NPU statistics miscount FTP sessions

    After FTP traffic passes, `npu-session stat` does not report the accurate number of active sessions.

  • #761754

    Down IPsec aggregate route remains active

    An IPsec aggregate static route is not marked inactive when the aggregate is down.

  • #945367

    ADVPN shortcuts do not inherit disabled source check

    Disabling `src-check` (RPF) on a parent tunnel is not inherited by ADVPN shortcuts.

  • #850642

    Concurrent configuration changes can suppress logs

    Traffic logs may be missing when numerous configuration changes occur simultaneously.

  • #1001497

    Invalid proxy HTTP date can trigger conserve mode

    FortiGate may enter conserve mode when a non-date or invalid HTTP date is posted through the web proxy.

  • #1117475

    Internal-browser SAML SSL VPN connection fails

    FortiClient cannot connect to FortiGate SSL VPN with SAML login when an internal browser is used as the SAML authentication user agent.

  • #614691

    Large Security Fabric topology slows GUI

    GUI performance is slow in a Fabric topology containing more than 50 downstream devices.

  • #794703

    Security Rating reports incorrect check results

    Security Rating reports show incorrect results for Rogue AP Detection and FortiCare Support checks.

  • #862424

    Security Rating can trigger conserve mode

    On FortiGates with large tables, such as more than 1,000 policies, addresses, or other objects, Security Rating reports may put the device into conserve mode.

  • #903922

    Large Fabric topology views load slowly

    Security Fabric physical and logical topology pages can load slowly with many downstream FortiGates, FortiSwitches, FortiAPs, and endpoint traffic. This is a GUI-only issue and does not affect downstream-device operation.

  • #847664

    Console may report machine-check hardware error

    The console may show `mce: [Hardware Error]` after a fresh image burn or reboot.

  • #861962

    One-gigabit aggregate interface cannot pass traffic

    When an 802.3ad aggregate is configured at 1 Gbps, its port LED may remain off and traffic cannot pass. Affected platforms are 110xE, 220xE, 330xE, 340xE, and 360xE.

  • #934708

    CMDB server can remain blocked on var_zone lock

    The cmdbsvr process may be unable to secure the `var_zone` lock because another process holds it indefinitely.

  • #935158

    Reboot emits missing GUI redirect file message

    After reboot, the console may print `check_gui_redir_file: No such file or directory`.

  • #975496

    FortiGate 200F is slow between 1G and 10G ports

    FortiGate 200F may experience slow uploads and downloads for traffic traversing from a 1G interface to a 10G interface.

  • #1117005

    IPsec NPU offload can cause CPU and management issues

    Certain FortiGate models may experience CPU spikes and management-access problems after upgrade when IPsec Phase 1 NPU offload is enabled during maintenance.

  • #1082256

    BIOS security level 2 can fail integrity check

    An upgrade from 7.0.15 to 7.0.16 with BIOS security level 2 can report 'System file integrity check failed!'.

  • #800935

    ESXi VLAN over LACP does not work

    An ESXi VLAN interface based on LACP does not work.

  • #1082304

    Selected VMs can hit kernel errors during upgrade

    FortiGate VMs for ARM64 KVM, AWS, OCI, and VM64 OPC can encounter a kernel error when upgrading from 7.0.15 to 7.0.16. The OCI bare-metal kernel image is unsupported in 7.0.16 when upgrading from 7.0.13, 7.0.14, or 7.0.15.

  • #766126

    Video filter does not inject block replacement page

    When video filtering blocks content, the replacement page is not pushed automatically to replace the video.

  • #814541

    Large FortiAP deployments load slowly in GUI

    With more than 500 managed FortiAPs and more than 5,000 WiFi clients, the Managed FortiAPs page and FortiAP Status widget can take a long time to load. FortiAP operation is unaffected.

  • #1004338

    NP7 WiFi DHCP relay traffic stops after restart

    After an upgrade or reboot on NP7 platforms, WiFi traffic cannot pass when the SSID VLAN interface uses DHCP Relay Server.

  • #819987

    ZTNA mapped drives fail after laptop reboot

    Mapped drives become inaccessible after a laptop reboots when using a FortiGate ZTNA access proxy with FQDN destinations.

  • #848222

    ZTNA TCP forwarding fails with FQDN real server

    ZTNA TCP forwarding does not work when the real server uses an FQDN address type. Fortinet does not recommend an FQDN that can resolve public IP addresses because an internal DNS database zone may override it; after reboot the private address may not take effect and the real server may not be found.