FortiOS 7.4.11 release notes

synced 2026-08-02

FortiOS 7.4.11 fixes CVE-2026-24858 and several NP7 QTM defects, changes how NP7-offloaded traffic selects TPE versus QTM shaping, and documents new and existing known issues.

Official Fortinet release notes ↗

What's new

  • NP7 QTM reliability improvements

    The Queuing based Traffic Management (QTM) module now fixes incorrect fragment checksums, hangs caused by packets longer than 6000 bytes, hangs during refresh, and failure to honor MTU and fragment packets after QTM.

Breaking changes

  • NP7 default QoS type is restricted to policing

    For NP7-offloaded sessions, `default-qos-type` can only be set to `policing`; administrators can no longer select `shaping` with `config system npu set default-qos-type {policing | shaping} end`.

  • NP7 traffic-shaping modules are selected by shaping mode

    For NP7 sessions, policy traffic shaping, per-IP shaping, and regular port shaping where `outbandwidth` is enabled without a shaping profile always use the NP7 accounting and traffic-shaping TPE module, equivalent to `default-qos-type policing`. Interface shaping profiles, also called Multiclass shaping (MCS), now use QTM exclusively, equivalent to `default-qos-type shaping`.

Security fixes

  • #1246654CVE-2026-24858

    FortiOS is no longer vulnerable to CVE-2026-24858

    Fortinet identifies this vulnerability fix under bug 1246654. Consult FortiGuard PSIRT for additional information.

Features removed

  • #903444

    Route-cache diagnostic is unsupported on the 4.19 kernel

    The command `diagnose ip rtcache list` is no longer supported in the FortiOS 4.19 kernel.

Upgrade notes

  • #1252663

    Older-BIOS D-series devices can lose their serial number

    After upgrade to FortiOS 7.4.10, 7.4.11, 7.6.5, or 7.6.6, affected D-series devices may report serial number `FGT0000000000001`.

Known issues

  • #977155

    HA synchronization fails with different private keys

    New in FortiOS 7.4.11.

  • #1282986

    FortiAnalyzer logs are unavailable on FortiGate

    When connected to FortiAnalyzer, its logs are not visible through the FortiGate GUI or CLI. New in FortiOS 7.4.11.

  • #1179259

    VXLAN TCP traffic is impacted by offload and UTM

    TCP traffic over VXLAN is impacted when both `auto-asic-offload` and UTM are enabled on the policy. Workaround: disable `auto-asic-offload` on the affected policy. New in FortiOS 7.4.11.

  • #1244268

    Fnbamd errors while following multiple AIA links

    An error occurs when downloading intermediate CAs through multiple Authority Information Access links. New in FortiOS 7.4.11.

  • #1298350

    DNS over TLS server appears unreachable

  • #1026362

    Captive-portal pages fail without persistent cookies

    Web pages do not load when `persistent-cookie` is disabled for session-cookie-based authentication with captive portal.

  • #959065

    Traffic-shaper changes clear other counters

    Creating or deleting a shaper on Policy & Objects > Traffic Shaping clears counters for the other shapers.

  • #1114635

    GUI CIDR filtering of address objects fails

    The GUI cannot correctly filter Address objects using CIDR notation.

  • #1256278

    SoC5 ingress shaping may lose packets

    Packet loss may occur on SoC5 FortiGate models when ASIC offloading is enabled and an ingress shaping profile is configured.

  • #911244

    FortiGate 7000E IPv6 routes may not synchronize

    IPv6 routes may not synchronize correctly among FIMs and FPMs.

  • #1006759

    IPsec kernel route is missing after HA failover

    Workaround: bring the tunnel down and then back up.

  • #1026665

    Some 7000F FPMs omit syslog test messages

    On FortiGate 7000F with virtual clustering and syslog configured, running a diagnose log test from a primary-vcluster VDOM may not produce messages from some FPMs.

  • #1048808

    SIP sessions do not resynchronize after secondary reboot

    After the secondary rejoins the cluster, SIP sessions are not resynchronized.

  • #1070365

    FortiManager can break 7000F HA session synchronization

    FortiManager may change management-interface VDOMs used by `set session-sync-dev 1-M1 1-M2` from `vsys_ha` to `mgmt-vdom`, stopping them from operating as session-sync interfaces. Workaround: reconfigure `session-sync-dev` on the cluster, then retrieve the FortiGate configuration into FortiManager.

  • #1092728

    FortiGate 7000F IPv6 fragments fail randomly

  • #1153360

    Platform counters may mismatch or overflow

    Counter values may not match totals and can overflow during continuous clearing on certain FortiGate models.

  • #1170524

    VDOM administrators cannot SSH through special ports

    SSH login attempts through special ports fail for VDOM administrators with `mgmt-vdom` access on SLBC FortiController models.

  • #1183170

    SD-WAN does not work in the management VDOM

  • #1185528

    Secondary chassis loses subscription license after upgrade

    The secondary chassis may lack its subscription license after a graceful upgrade from 7.2.10 to 7.2.12. Workaround: run `execute update-now` again.

  • #1123502

    FortiView malicious-site drill-down fails

    FortiView Threats may report that it failed to retrieve FortiView data from disk when drilling into a malicious website entry.

  • #853352

    Large Internet Service Database entries cannot be fully scrolled

    The GUI slide-out cannot reach the end when an Internet Service Database entry contains more than 100,000 items.

  • #885427

    Working SFP port appears disabled in faceplate view

    This is a GUI-only display problem. Workaround: view SFP status in the CLI interface list.

  • #1071907

    NPU vlink type is unavailable in the GUI

    The GUI has no setting for the `type` option on an `npu_vlink` interface.

  • #1145907

    Bandwidth widget misreports backup VLAN traffic

  • #1153294

    Custom login-page HTML renders incorrectly

    Custom HTML content configured through the GUI or CLI does not render correctly on login pages.

  • #1237136

    Dynamic VLANs disappear from the GUI

    Dynamic VLANs are not visible in the GUI when a port-security policy is applied.

  • #781171

    HA GUI may falsely report upgrade failure

    If the secondary takes several minutes to boot, a premature timeout can display "Image upgrade failed" even though the HA upgrade can complete successfully.

  • #1135376

    HA contract retrieval requires one FortiCare account

    If HA members are not registered under the same FortiCare account, the cluster cannot retrieve contract information for all members from FortiGuard.

  • #1210147

    Certificate causes HA configuration mismatch

    HA can become out of sync due to a certificate.

  • #1226122

    Secondary HA GUI lacks an upgrade button

    The button is absent in local-only or secondary-only MVC upgrade mode. Workaround: upgrade the secondary from the CLI.

  • #1231480

    Monitored-port HA failover disrupts LACPDU transmission

  • #1025908

    FGSP peer session count is halved

    In new VRRP-based FGSP setups, the peer reports approximately 50% fewer sessions.

  • #1091815

    Hardware session synchronization fails when a member is down

    Hardware sessions may not synchronize when one of multiple `hw-session-sync-dev` interfaces is down.

  • #1119021

    Session-sync daemon reports a physically down device as up

    The issue affects hardware session-sync devices and not software session-sync devices.

  • #1119031

    Hardware sessions do not synchronize to the secondary

    On 4201, hardware sessions are not synchronized when a member of `hw-session-sync-dev` is down.

  • #1150863

    HA failover may delete sessions unintentionally

    A dirty Rsession can cause unintended session deletion after FGSP failover.

  • #1184045

    IPv6 High Security policy can block TCP and UDP

    Using a threat-feed object in an IPv6 High Security policy can incorrectly disable IPv6 functionality and prevent TCP/UDP traffic.

  • #1197891

    Unsupported session-sync ports break hardware synchronization

    Configuring unsupported ports for `hw-session-sync-dev` can stop hardware session synchronization. Workaround: change the interface and reboot; correcting the configuration alone does not restore operation.

  • #1199557

    Unsupported interfaces are accepted in session-sync LAGs

    Unsupported network interfaces can be added to a LAG configured for hardware session synchronization, creating potentially invalid configurations.

  • #1200885

    Renaming an IP pool can affect VDOM traffic

    Renaming an IP pool in a VDOM deployment can cause unintended network-traffic behavior.

  • #1201968

    Log2host table can leak memory after failovers

    On 4401F, approximately 60 million connections with log2host configured and repeated failovers can produce a memory leak.

  • #1202268

    Failover leaves hardware sessions unsynchronized

    On 4401F, not all hardware sessions are synchronized to the new secondary after failover.

  • #866413

    GRE-over-IPsec traffic is not NP7-offloaded

    GRE over IPsec, or IPsec traffic with GRE encapsulation, is not offloaded on NP7-based units.

  • #897871

    GRE over IPsec fails in transport mode

  • #970703

    6000 and 7000 platforms lack IPsec over vdom-link

    IPsec VPN over `vdom-link` or `npu-vlink` is unsupported on FortiGate 6000/7000 platforms.

  • #1036262

    UDP IPsec traffic uses FortiGate-ESP unexpectedly

    Tunnel traffic is encrypted as FortiGate-ESP packets when transport is UDP and FortiGate-ESP is enabled. Workaround: disable `fortinet-esp` when transport is set to `udp`.

  • #1035490

    Two-gigabyte models require reboot after proxy-mode upgrade

    Proxy-based inspection policies on FortiGate models with 2 GB RAM require a reboot after upgrade.

  • #1154124

    FortiNAC API cannot add dynamic fabric addresses

    REST API requests fail because of HTTP-header validation.

  • #1040655

    ECMP may change the egress path of local-out traffic

    Since 7.4.1, local-out traffic can use different ECMP routes or ports. For source-sensitive traffic, specify an interface or SD-WAN, for example: `config system fortiguard set interface-select-method specify set interface "wan1" end`.

  • #1133796

    IPv6 routes remain stuck in the kernel table

  • #1150878

    IPoE tunnel is unavailable in Bandwidth widget

    The IPoE tunnel interface cannot be selected in the Interface Bandwidth widget.

  • #1076439

    Asset Identity Center cannot load user-device data

    Security Fabric Asset Identity Center displays "Failed to load user device store data".

  • #1156006

    HA automation-stitch SFTP backups fail with Windows paths

    SFTP backup can fail when triggered by an automation stitch on an HA FortiGate using Windows-style paths.

  • #1150215

    FortiSwitch status differs between topology and list views

    Offline FortiSwitches appear offline in the topology but online in the list.

  • #1021903

    LAN-extension member list does not follow role changes

    The `le-switch` member list is not updated after an interface role changes in a LAN-extension environment.

  • #1078541

    Fresh image burn can hang FortiFirewall 2600F

    A fresh image burn may leave a FortiFirewall 2600F stuck, though upgrades from previous releases work. Workaround: power-cycle the unit.

  • #1085407

    QoS shaping setting can make FortiGate unresponsive

    A FortiGate may become unresponsive when `default-qos-type` is set to `shaping`.

  • #1105321

    4201F NPU ingress and softirq utilization can stick at 100%

    NP7 `EIF0_IGR` and `EIF1_IGR` usage may remain at 100%, with host softirq near 99%, after IP-tunnel traffic.

  • #1114298

    FortiGate Cloud remote login creates duplicate events

    Remote login produces one successful administrator event and one unsuccessful PKI-administrator event.

  • #1136616

    Some VLAN interfaces lack dashboard graphs

  • #1164332

    NP7 stops forwarding after large-packet reassembly

    NP7 can cease forwarding traffic after reassembling a large packet in DFR.

  • #1203193

    Rugged 70G models lack DIO automation-condition CLI

    When DIO module alarm functionality is active on FGR-70G and FGR-70G-5G-Dual, `set condition-type input` is unavailable under `config system automation-condition`.

  • #1213236

    700G port-speed migration can leave interfaces down

    After upgrading from 7.2.x behavior, FGT700G/701G `wan1`, `wan2`, and `lan1`-`lan6` may remain at `5000auto`, which in 7.4.9 operates only at 5000 Mb/s rather than negotiating to 1 Gb/s. Workaround: manually set port speed to `auto`.

  • #1227167

    Node process can cause high memory usage

    Workaround: enable automatic web-service restart with `config system global set web-svc-auto-restart enable end`.

  • #1260308

    SYN flood detection can cause high memory usage

    Workaround: configure an ACL to drop the known denial-of-service traffic.

  • #1283008

    BMR hostname is not updated for an active VNE tunnel

  • #1114550

    FortiExtender appears offline after FortiGate upgrade

    Observed after upgrading FortiGate from 7.4.5 GA to 7.4.6 GA. Workaround: manually reboot FortiExtender.

  • #1135049

    Database update can race with CMDB loading after upgrade

    After a FortiOS upgrade, the update daemon may update databases while CMDB is loading its JSON file, producing an error condition.

  • #884462

    Chrome NTLM authentication fails

  • #972391

    GUI misreports RADIUS group use for administrators

    RADIUS group usage is not displayed correctly when the group is used for firewall-administrator authentication.

  • #1082800

    Large LDAP GUI searches can freeze FortiGate

    Searching an LDAP server with over 100,000 users from the GUI can make HTTPSD consume excessive memory, slowing or freezing the device and potentially requiring HTTPSD termination or reboot. Workaround: search through the CLI.

  • #1148767

    FSSO user display and filtering are incorrect

    User names appear in lowercase, filtering does not work, and pie charts are not visible.

  • #1157003

    Agentless FSSO has issues with Windows 2025

    Additional Microsoft restrictions on remote Event Log reading affect the connector.

  • #978021

    GWLB FTP passive SYN-ACK has a zero-length VNI

    In FTP passive mode with a GWLB deployment, Geneve-header VNI lengths are zero in SYN-ACK packets, causing retransmissions.

  • #1125437

    DHCP interface distance setting fails on VM

    The `set distance` option under an interface configured as a DHCP client does not work on virtual machines.

  • #1244347

    Azure FortiGate VM trusted launch fails

    FGT_VM64_AZURE fails trusted launch on Azure.

  • #1245936

    VM license validation fails through IPv6 FortiManager

    FortiGate VM cannot validate its license from a FortiManager addressed through IPv6.

  • #814541

    Large FortiAP deployments load slowly in the GUI

    With more than 500 managed FortiAPs and 5,000 clients, Managed FortiAP and FortiAP Status can take a long time to load; FortiAP operation is unaffected.

  • #964757

    Specific SSID connections lack debug and sniffer logs

    Station logs may show RADIUS requests and challenges while the FortiGate fails to produce debug or sniffer logs for the affected user.

  • #1080094

    Stale offline WiFi stations can consume memory

    Offline station entries are not automatically cleaned up and may cause high memory usage.

  • #1144969

    WiFi Client GUI shows mismatched IP details

  • #819987

    ZTNA mapped drives fail after laptop reboot

    Mapped drives become inaccessible after reboot when using a FortiGate ZTNA access proxy with FQDN destinations.

Special notices

  • NP7 interface shaping profiles have a 100-interface limit

    QTM-based shaping profiles are supported on physical, LAG, and VLAN interfaces over physical or LAG interfaces. A FortiGate supports shaping profiles on at most 100 interfaces.