FortiOS 7.4.11 release notes
FortiOS 7.4.11 fixes CVE-2026-24858 and several NP7 QTM defects, changes how NP7-offloaded traffic selects TPE versus QTM shaping, and documents new and existing known issues.
Official Fortinet release notes ↗What's new
NP7 QTM reliability improvements
The Queuing based Traffic Management (QTM) module now fixes incorrect fragment checksums, hangs caused by packets longer than 6000 bytes, hangs during refresh, and failure to honor MTU and fragment packets after QTM.
Breaking changes
NP7 default QoS type is restricted to policing
For NP7-offloaded sessions, `default-qos-type` can only be set to `policing`; administrators can no longer select `shaping` with `config system npu set default-qos-type {policing | shaping} end`.
NP7 traffic-shaping modules are selected by shaping mode
For NP7 sessions, policy traffic shaping, per-IP shaping, and regular port shaping where `outbandwidth` is enabled without a shaping profile always use the NP7 accounting and traffic-shaping TPE module, equivalent to `default-qos-type policing`. Interface shaping profiles, also called Multiclass shaping (MCS), now use QTM exclusively, equivalent to `default-qos-type shaping`.
Security fixes
- #1246654CVE-2026-24858
FortiOS is no longer vulnerable to CVE-2026-24858
Fortinet identifies this vulnerability fix under bug 1246654. Consult FortiGuard PSIRT for additional information.
Features removed
- #903444
Route-cache diagnostic is unsupported on the 4.19 kernel
The command `diagnose ip rtcache list` is no longer supported in the FortiOS 4.19 kernel.
Upgrade notes
- #1252663
Older-BIOS D-series devices can lose their serial number
After upgrade to FortiOS 7.4.10, 7.4.11, 7.6.5, or 7.6.6, affected D-series devices may report serial number `FGT0000000000001`.
Known issues
- #977155
HA synchronization fails with different private keys
New in FortiOS 7.4.11.
- #1282986
FortiAnalyzer logs are unavailable on FortiGate
When connected to FortiAnalyzer, its logs are not visible through the FortiGate GUI or CLI. New in FortiOS 7.4.11.
- #1179259
VXLAN TCP traffic is impacted by offload and UTM
TCP traffic over VXLAN is impacted when both `auto-asic-offload` and UTM are enabled on the policy. Workaround: disable `auto-asic-offload` on the affected policy. New in FortiOS 7.4.11.
- #1244268
Fnbamd errors while following multiple AIA links
An error occurs when downloading intermediate CAs through multiple Authority Information Access links. New in FortiOS 7.4.11.
- #1298350
DNS over TLS server appears unreachable
- #1026362
Captive-portal pages fail without persistent cookies
Web pages do not load when `persistent-cookie` is disabled for session-cookie-based authentication with captive portal.
- #959065
Traffic-shaper changes clear other counters
Creating or deleting a shaper on Policy & Objects > Traffic Shaping clears counters for the other shapers.
- #1114635
GUI CIDR filtering of address objects fails
The GUI cannot correctly filter Address objects using CIDR notation.
- #1256278
SoC5 ingress shaping may lose packets
Packet loss may occur on SoC5 FortiGate models when ASIC offloading is enabled and an ingress shaping profile is configured.
- #911244
FortiGate 7000E IPv6 routes may not synchronize
IPv6 routes may not synchronize correctly among FIMs and FPMs.
- #1006759
IPsec kernel route is missing after HA failover
Workaround: bring the tunnel down and then back up.
- #1026665
Some 7000F FPMs omit syslog test messages
On FortiGate 7000F with virtual clustering and syslog configured, running a diagnose log test from a primary-vcluster VDOM may not produce messages from some FPMs.
- #1048808
SIP sessions do not resynchronize after secondary reboot
After the secondary rejoins the cluster, SIP sessions are not resynchronized.
- #1070365
FortiManager can break 7000F HA session synchronization
FortiManager may change management-interface VDOMs used by `set session-sync-dev 1-M1 1-M2` from `vsys_ha` to `mgmt-vdom`, stopping them from operating as session-sync interfaces. Workaround: reconfigure `session-sync-dev` on the cluster, then retrieve the FortiGate configuration into FortiManager.
- #1092728
FortiGate 7000F IPv6 fragments fail randomly
- #1153360
Platform counters may mismatch or overflow
Counter values may not match totals and can overflow during continuous clearing on certain FortiGate models.
- #1170524
VDOM administrators cannot SSH through special ports
SSH login attempts through special ports fail for VDOM administrators with `mgmt-vdom` access on SLBC FortiController models.
- #1183170
SD-WAN does not work in the management VDOM
- #1185528
Secondary chassis loses subscription license after upgrade
The secondary chassis may lack its subscription license after a graceful upgrade from 7.2.10 to 7.2.12. Workaround: run `execute update-now` again.
- #1123502
FortiView malicious-site drill-down fails
FortiView Threats may report that it failed to retrieve FortiView data from disk when drilling into a malicious website entry.
- #853352
Large Internet Service Database entries cannot be fully scrolled
The GUI slide-out cannot reach the end when an Internet Service Database entry contains more than 100,000 items.
- #885427
Working SFP port appears disabled in faceplate view
This is a GUI-only display problem. Workaround: view SFP status in the CLI interface list.
- #1071907
NPU vlink type is unavailable in the GUI
The GUI has no setting for the `type` option on an `npu_vlink` interface.
- #1145907
Bandwidth widget misreports backup VLAN traffic
- #1153294
Custom login-page HTML renders incorrectly
Custom HTML content configured through the GUI or CLI does not render correctly on login pages.
- #1237136
Dynamic VLANs disappear from the GUI
Dynamic VLANs are not visible in the GUI when a port-security policy is applied.
- #781171
HA GUI may falsely report upgrade failure
If the secondary takes several minutes to boot, a premature timeout can display "Image upgrade failed" even though the HA upgrade can complete successfully.
- #1135376
HA contract retrieval requires one FortiCare account
If HA members are not registered under the same FortiCare account, the cluster cannot retrieve contract information for all members from FortiGuard.
- #1210147
Certificate causes HA configuration mismatch
HA can become out of sync due to a certificate.
- #1226122
Secondary HA GUI lacks an upgrade button
The button is absent in local-only or secondary-only MVC upgrade mode. Workaround: upgrade the secondary from the CLI.
- #1231480
Monitored-port HA failover disrupts LACPDU transmission
- #1025908
FGSP peer session count is halved
In new VRRP-based FGSP setups, the peer reports approximately 50% fewer sessions.
- #1091815
Hardware session synchronization fails when a member is down
Hardware sessions may not synchronize when one of multiple `hw-session-sync-dev` interfaces is down.
- #1119021
Session-sync daemon reports a physically down device as up
The issue affects hardware session-sync devices and not software session-sync devices.
- #1119031
Hardware sessions do not synchronize to the secondary
On 4201, hardware sessions are not synchronized when a member of `hw-session-sync-dev` is down.
- #1150863
HA failover may delete sessions unintentionally
A dirty Rsession can cause unintended session deletion after FGSP failover.
- #1184045
IPv6 High Security policy can block TCP and UDP
Using a threat-feed object in an IPv6 High Security policy can incorrectly disable IPv6 functionality and prevent TCP/UDP traffic.
- #1197891
Unsupported session-sync ports break hardware synchronization
Configuring unsupported ports for `hw-session-sync-dev` can stop hardware session synchronization. Workaround: change the interface and reboot; correcting the configuration alone does not restore operation.
- #1199557
Unsupported interfaces are accepted in session-sync LAGs
Unsupported network interfaces can be added to a LAG configured for hardware session synchronization, creating potentially invalid configurations.
- #1200885
Renaming an IP pool can affect VDOM traffic
Renaming an IP pool in a VDOM deployment can cause unintended network-traffic behavior.
- #1201968
Log2host table can leak memory after failovers
On 4401F, approximately 60 million connections with log2host configured and repeated failovers can produce a memory leak.
- #1202268
Failover leaves hardware sessions unsynchronized
On 4401F, not all hardware sessions are synchronized to the new secondary after failover.
- #866413
GRE-over-IPsec traffic is not NP7-offloaded
GRE over IPsec, or IPsec traffic with GRE encapsulation, is not offloaded on NP7-based units.
- #897871
GRE over IPsec fails in transport mode
- #970703
6000 and 7000 platforms lack IPsec over vdom-link
IPsec VPN over `vdom-link` or `npu-vlink` is unsupported on FortiGate 6000/7000 platforms.
- #1036262
UDP IPsec traffic uses FortiGate-ESP unexpectedly
Tunnel traffic is encrypted as FortiGate-ESP packets when transport is UDP and FortiGate-ESP is enabled. Workaround: disable `fortinet-esp` when transport is set to `udp`.
- #1035490
Two-gigabyte models require reboot after proxy-mode upgrade
Proxy-based inspection policies on FortiGate models with 2 GB RAM require a reboot after upgrade.
- #1154124
FortiNAC API cannot add dynamic fabric addresses
REST API requests fail because of HTTP-header validation.
- #1040655
ECMP may change the egress path of local-out traffic
Since 7.4.1, local-out traffic can use different ECMP routes or ports. For source-sensitive traffic, specify an interface or SD-WAN, for example: `config system fortiguard set interface-select-method specify set interface "wan1" end`.
- #1133796
IPv6 routes remain stuck in the kernel table
- #1150878
IPoE tunnel is unavailable in Bandwidth widget
The IPoE tunnel interface cannot be selected in the Interface Bandwidth widget.
- #1076439
Asset Identity Center cannot load user-device data
Security Fabric Asset Identity Center displays "Failed to load user device store data".
- #1156006
HA automation-stitch SFTP backups fail with Windows paths
SFTP backup can fail when triggered by an automation stitch on an HA FortiGate using Windows-style paths.
- #1150215
FortiSwitch status differs between topology and list views
Offline FortiSwitches appear offline in the topology but online in the list.
- #1021903
LAN-extension member list does not follow role changes
The `le-switch` member list is not updated after an interface role changes in a LAN-extension environment.
- #1078541
Fresh image burn can hang FortiFirewall 2600F
A fresh image burn may leave a FortiFirewall 2600F stuck, though upgrades from previous releases work. Workaround: power-cycle the unit.
- #1085407
QoS shaping setting can make FortiGate unresponsive
A FortiGate may become unresponsive when `default-qos-type` is set to `shaping`.
- #1105321
4201F NPU ingress and softirq utilization can stick at 100%
NP7 `EIF0_IGR` and `EIF1_IGR` usage may remain at 100%, with host softirq near 99%, after IP-tunnel traffic.
- #1114298
FortiGate Cloud remote login creates duplicate events
Remote login produces one successful administrator event and one unsuccessful PKI-administrator event.
- #1136616
Some VLAN interfaces lack dashboard graphs
- #1164332
NP7 stops forwarding after large-packet reassembly
NP7 can cease forwarding traffic after reassembling a large packet in DFR.
- #1203193
Rugged 70G models lack DIO automation-condition CLI
When DIO module alarm functionality is active on FGR-70G and FGR-70G-5G-Dual, `set condition-type input` is unavailable under `config system automation-condition`.
- #1213236
700G port-speed migration can leave interfaces down
After upgrading from 7.2.x behavior, FGT700G/701G `wan1`, `wan2`, and `lan1`-`lan6` may remain at `5000auto`, which in 7.4.9 operates only at 5000 Mb/s rather than negotiating to 1 Gb/s. Workaround: manually set port speed to `auto`.
- #1227167
Node process can cause high memory usage
Workaround: enable automatic web-service restart with `config system global set web-svc-auto-restart enable end`.
- #1260308
SYN flood detection can cause high memory usage
Workaround: configure an ACL to drop the known denial-of-service traffic.
- #1283008
BMR hostname is not updated for an active VNE tunnel
- #1114550
FortiExtender appears offline after FortiGate upgrade
Observed after upgrading FortiGate from 7.4.5 GA to 7.4.6 GA. Workaround: manually reboot FortiExtender.
- #1135049
Database update can race with CMDB loading after upgrade
After a FortiOS upgrade, the update daemon may update databases while CMDB is loading its JSON file, producing an error condition.
- #884462
Chrome NTLM authentication fails
- #972391
GUI misreports RADIUS group use for administrators
RADIUS group usage is not displayed correctly when the group is used for firewall-administrator authentication.
- #1082800
Large LDAP GUI searches can freeze FortiGate
Searching an LDAP server with over 100,000 users from the GUI can make HTTPSD consume excessive memory, slowing or freezing the device and potentially requiring HTTPSD termination or reboot. Workaround: search through the CLI.
- #1148767
FSSO user display and filtering are incorrect
User names appear in lowercase, filtering does not work, and pie charts are not visible.
- #1157003
Agentless FSSO has issues with Windows 2025
Additional Microsoft restrictions on remote Event Log reading affect the connector.
- #978021
GWLB FTP passive SYN-ACK has a zero-length VNI
In FTP passive mode with a GWLB deployment, Geneve-header VNI lengths are zero in SYN-ACK packets, causing retransmissions.
- #1125437
DHCP interface distance setting fails on VM
The `set distance` option under an interface configured as a DHCP client does not work on virtual machines.
- #1244347
Azure FortiGate VM trusted launch fails
FGT_VM64_AZURE fails trusted launch on Azure.
- #1245936
VM license validation fails through IPv6 FortiManager
FortiGate VM cannot validate its license from a FortiManager addressed through IPv6.
- #814541
Large FortiAP deployments load slowly in the GUI
With more than 500 managed FortiAPs and 5,000 clients, Managed FortiAP and FortiAP Status can take a long time to load; FortiAP operation is unaffected.
- #964757
Specific SSID connections lack debug and sniffer logs
Station logs may show RADIUS requests and challenges while the FortiGate fails to produce debug or sniffer logs for the affected user.
- #1080094
Stale offline WiFi stations can consume memory
Offline station entries are not automatically cleaned up and may cause high memory usage.
- #1144969
WiFi Client GUI shows mismatched IP details
- #819987
ZTNA mapped drives fail after laptop reboot
Mapped drives become inaccessible after reboot when using a FortiGate ZTNA access proxy with FQDN destinations.
Special notices
NP7 interface shaping profiles have a 100-interface limit
QTM-based shaping profiles are supported on physical, LAG, and VLAN interfaces over physical or LAG interfaces. A FortiGate supports shaping profiles on at most 100 interfaces.