FortiOS 7.0.19 release notes
FortiOS 7.0.19 is a security-focused release that fixes CVE-2026-24858. Fortinet lists no new known issues, but 62 issues from earlier releases remain. Upgrade paths are model- and source-version-specific and must be checked with Fortinet's Upgrade Path Tool.
Official Fortinet release notes ↗Security fixes
- #1246654CVE-2026-24858
CVE-2026-24858 fixed
FortiOS 7.0.19 is no longer vulnerable to CVE-2026-24858. Fortinet directs users to https://fortiguard.com/psirt for additional information.
Upgrade notes
Use Fortinet Upgrade Path Tool before upgrading
Supported upgrade paths depend on the FortiGate model, currently installed FortiOS version, and target version. In the Fortinet Document Library, open Tools & Resources > Upgrade Path Tool, select FortiGate / FortiOS, choose the model, current version, and target version, then select Go. Tool: https://docs.fortinet.com/upgrade-tool/.
Known issues
No new known issues in 7.0.19
Fortinet states that no new issues have been identified specifically in version 7.0.19; the remaining known issues originated in previous FortiOS versions.
- #843554
GUI can silently alter an IP-type firewall service
If the first firewall service object in CLI table order has protocol type IP, creating another IP-type service in the GUI may incorrectly change the first object's protocol number. This can affect policies using that service, including the ALL service on some 6000/7000 platforms. Workaround: create the service through the CLI or move a non-IP service before it, for example: `config firewall service custom edit "unused" set tcp-portrange 1 next move "unused" before "ALL" end`.
- #912740
FortiManager-managed policies may split into separate groups
After upgrade to 7.0.13, a FortiManager-managed FortiGate may show separate sequence groups because each policy receives a unique `global-label`. Workaround: drag policies into the correct sequence group in the GUI, or remove `global-label` from each member except the leading policy.
- #951984
Local-out DNAT may select no best output route
The best output route may not be found for local-out DNAT traffic.
- #951135
Graceful 6000/7000 HA upgrade path is unsupported
Graceful upgrade of a FortiGate 6000/7000 FGCP HA cluster from 7.0.12 to 7.2.5 or 7.2.6 is unsupported. Use a maintenance window because traffic can be disrupted for up to 30 minutes. Disable `uninterruptible-upgrade` and perform a normal firmware upgrade; traffic remains unavailable until all management boards and FPCs, or FIMs and FPMs, are upgraded and both FortiGates restart.
- #963201
One-to-One NAT policy can create traffic-flow conflicts
There is a traffic-flow conflict risk when One-to-One is used as a NAT policy.
- #987672
DEI-marked fragments do not work on 6000/7000
Fragment packets with `DEI == 1` do not work on the FortiGate 6000/7000 platform.
- #941521
FortiView category filter fails in Japanese GUI
The Category filter on Dashboard > FortiView Websites does not work when using the Japanese GUI.
- #440197
Working FortiGuard override server displays Unknown
On System > FortiGuard, the override server for AntiVirus & IPS Updates may display Unknown even when working. This is display-only and does not affect override operation.
- #677806
Global interface view misreports IPsec tunnel status
With VDOM mode enabled, Network > Interfaces in Global view may show IPsec tunnel interfaces from non-management VDOMs as UP incorrectly. The VDOM view reports the correct state.
- #685431
Large firewall policy lists load slowly
Policy & Objects > Firewall Policy can require about 30 seconds or longer to load with more than 20,000 policies. Workaround: configure policies through the CLI.
- #707589
Certificate reference count and deletion status can be wrong
System > Certificates can show an incorrect reference count and permit an attempted deletion of a referenced certificate. Deletion fails despite a success message; remove all references before deleting.
- #708005
Firefox cannot paste into SSL VPN SSH terminal
Users cannot paste text into the SSL VPN web portal SSH terminal emulator in Firefox. Workaround: use Chrome, Edge, or Safari.
- #755177
GUI warns incorrectly about 7.0.1-to-7.0.2 path
When upgrading from 7.0.1 to 7.0.2, the GUI can incorrectly say that the upgrade path is invalid.
- #810225
First administrator password change shows undefined error
An undefined error appears when an administrator password is changed for the first time on NP7 platforms.
- #853352
Internet Service Database pane cannot reach final entries
The View/Edit Entries pane under Policy & Objects > Internet Service Database cannot scroll to the end when it contains more than 100,000 entries.
- #881678
GUI cannot edit very large prefix lists
Editing a prefix list with many rules under Network > Routing Objects fails with 'The integer value is not within valid range'. Workaround: edit the prefix list through the CLI.
- #898902
Two-factor toggle loads slowly with many VDOMs
With more than 200 VDOMs, System > Administrators can take over one minute to load the Two-factor Authentication toggle. Other settings are unaffected. Workaround: configure `two-factor-authentication` under `config system admin` in the CLI.
- #974988
GUI may show an incorrect FortiManager Cloud expiry
The GUI may report an expired device-level FortiManager Cloud license even when the account-level license remains valid. Functionality is unaffected.
- #1102588
High security level blocks graceful secondary-node upgrade
On FortiGate 12xG and 9xG devices, graceful upgrade of the secondary HA node fails when security level is high. Workaround: disable HA and upgrade units separately, or lower the security level, upgrade, and restore it to high.
- #771857
Hyperscale policies expose unsupported VIP options
Hyperscale firewall policies do not support VIP features `srcfltr`, `srcintf-fltr`, `service`, `arp-reply`, `nat-source-vip`, and `portforwarding`, although they remain visible in the CLI or GUI for IPv4 and IPv6 VIPs in a hyperscale VDOM.
- #811109
Selected hyperscale platform ports cannot join an LAG
HA1, HA2, AUX1, and AUX2 interfaces cannot be added to an LAG on FortiGate 4200F, 4201F, 4400F, and 4401F.
- #836976
Changing hyperscale log processor can drop sessions
Sessions may be dropped when dynamically changing `log-processor` from `hardware` to `host` for a hardware log server used by a hyperscale policy. Make this change during a quiet period.
- #838654
Implicit-deny hit count fails for NAT46 and NAT64
The implicit-deny policy hit count does not increment for hardware sessions involving NAT46 or NAT64 traffic.
- #842659
IPv6 FTS address negation is unreliable
`srcaddr-negate` and `dstaddr-negate` do not work correctly for IPv6 traffic with FTS.
- #843132
New hyperscale ACLs can take effect late
ACL policies added to a traffic-processing hyperscale VDOM may take longer than expected to become effective. During the transition, traffic intended to be blocked may be allowed.
- #843197
NPU session list omits policy-route data
The NPU session list does not show policy-route information when accelerated traffic is routed through a policy route.
- #843266
Hyperscale diagnostic data is unavailable
A diagnostic command is not available to show `hit_count` and `last_used` for policy routes and NPU sessions in a hyperscale VDOM.
- #843305
Hyperscale boot emits PBR parse error
The console can log `PARSE SKIP ERROR=17 NPD ERR PBR ADDRESS` during system startup.
- #844421
IP pool diagnostic output is incorrect
`diagnose firewall ippool list` does not produce correct output for overload-type IP pools.
- #845269
GUI disables CGN endpoint-independent filtering
Editing a hyperscale policy with an overload CGN IP pool in the GUI disables `cgn-eif`, regardless of its previous state.
- #846520
NPD or LPMD can be killed after failover
The out-of-memory killer may terminate NPD or LPMD after mixed-session traffic and an HA failover.
- #895951
EIF session setup rate displays zero
`diagnose sys npu-session stat` incorrectly reports a `setup rate` of `0` for EIF sessions.
- #941784
Hyperscale hardware sessions fail to synchronize
Hardware-session synchronization does not work on FG-480xF devices in hyperscale mode.
- #986656
Primary HA NPU session state reports zero
On the HA primary unit, the NPU session list may contain many sessions while NPU session state reports `0`.
- #993343
NAT46 fragment-header setting can interrupt kernel
In a hyperscale VDOM, the kernel can encounter an interruption when `set nat46-generate-ipv6-fragment-header` is enabled.
- #1024902
NPU statistics miscount FTP sessions
After FTP traffic passes, `npu-session stat` does not report the accurate number of active sessions.
- #761754
Down IPsec aggregate route remains active
An IPsec aggregate static route is not marked inactive when the aggregate is down.
- #945367
ADVPN shortcuts do not inherit disabled source check
Disabling `src-check` (RPF) on a parent tunnel is not inherited by ADVPN shortcuts.
- #850642
Concurrent configuration changes can suppress logs
Traffic logs may be missing when numerous configuration changes occur simultaneously.
- #1001497
Invalid proxy HTTP date can trigger conserve mode
FortiGate may enter conserve mode when a non-date or invalid HTTP date is posted through the web proxy.
- #1117475
Internal-browser SAML SSL VPN connection fails
FortiClient cannot connect to FortiGate SSL VPN with SAML login when an internal browser is used as the SAML authentication user agent.
- #614691
Large Security Fabric topology slows GUI
GUI performance is slow in a Fabric topology containing more than 50 downstream devices.
- #794703
Security Rating reports incorrect check results
Security Rating reports show incorrect results for Rogue AP Detection and FortiCare Support checks.
- #862424
Security Rating can trigger conserve mode
On FortiGates with large tables, such as more than 1,000 policies, addresses, or other objects, Security Rating reports may put the device into conserve mode.
- #903922
Large Fabric topology views load slowly
Security Fabric physical and logical topology pages can load slowly with many downstream FortiGates, FortiSwitches, FortiAPs, and endpoint traffic. This is a GUI-only issue and does not affect downstream-device operation.
- #847664
Console may report machine-check hardware error
The console may show `mce: [Hardware Error]` after a fresh image burn or reboot.
- #861962
One-gigabit aggregate interface cannot pass traffic
When an 802.3ad aggregate is configured at 1 Gbps, its port LED may remain off and traffic cannot pass. Affected platforms are 110xE, 220xE, 330xE, 340xE, and 360xE.
- #934708
CMDB server can remain blocked on var_zone lock
The cmdbsvr process may be unable to secure the `var_zone` lock because another process holds it indefinitely.
- #935158
Reboot emits missing GUI redirect file message
After reboot, the console may print `check_gui_redir_file: No such file or directory`.
- #975496
FortiGate 200F is slow between 1G and 10G ports
FortiGate 200F may experience slow uploads and downloads for traffic traversing from a 1G interface to a 10G interface.
- #1117005
IPsec NPU offload can cause CPU and management issues
Certain FortiGate models may experience CPU spikes and management-access problems after upgrade when IPsec Phase 1 NPU offload is enabled during maintenance.
- #1082256
BIOS security level 2 can fail integrity check
An upgrade from 7.0.15 to 7.0.16 with BIOS security level 2 can report 'System file integrity check failed!'.
- #800935
ESXi VLAN over LACP does not work
An ESXi VLAN interface based on LACP does not work.
- #1082304
Selected VMs can hit kernel errors during upgrade
FortiGate VMs for ARM64 KVM, AWS, OCI, and VM64 OPC can encounter a kernel error when upgrading from 7.0.15 to 7.0.16. The OCI bare-metal kernel image is unsupported in 7.0.16 when upgrading from 7.0.13, 7.0.14, or 7.0.15.
- #766126
Video filter does not inject block replacement page
When video filtering blocks content, the replacement page is not pushed automatically to replace the video.
- #814541
Large FortiAP deployments load slowly in GUI
With more than 500 managed FortiAPs and more than 5,000 WiFi clients, the Managed FortiAPs page and FortiAP Status widget can take a long time to load. FortiAP operation is unaffected.
- #1004338
NP7 WiFi DHCP relay traffic stops after restart
After an upgrade or reboot on NP7 platforms, WiFi traffic cannot pass when the SSID VLAN interface uses DHCP Relay Server.
- #819987
ZTNA mapped drives fail after laptop reboot
Mapped drives become inaccessible after a laptop reboots when using a FortiGate ZTNA access proxy with FQDN destinations.
- #848222
ZTNA TCP forwarding fails with FQDN real server
ZTNA TCP forwarding does not work when the real server uses an FQDN address type. Fortinet does not recommend an FQDN that can resolve public IP addresses because an internal DNS database zone may override it; after reboot the private address may not take effect and the real server may not be found.