Network Security · H7 Labs · UAE
FortiOS 7.2 reached end of support on 30 September. If your firewall is still on it, read this.
No more fixes. No more support. Not even for critical security vulnerabilities. Here is what that actually means, and what to do about it this month.
On 30 September 2026, FortiOS 7.2 reached End of Support. That is the end of the line — not a warning, not a deprecation notice. After this date Fortinet provides no fixes of any kind for that release, including critical and security fixes, and no technical support.
If your FortiGate is running 7.2, it is now a permanently unpatched device sitting at the edge of your network.
Regular maintenance for 7.2 actually stopped on 31 March 2025. It has been on critical fixes only for eighteen months. Most organisations we speak to did not know that either.
Why this matters more than a normal firmware update
We know exactly how this plays out, because it already happened once.
FortiOS 7.0 reached End of Support on 30 September 2025. Within ten months, an actively exploited vulnerability appeared in it — serious enough to be listed in the US cybersecurity agency's known-exploited catalogue. Fortinet fixed it in supported releases only. For anyone still on 7.0, the only remedy offered was migration.
There are already four FortiOS vulnerabilities in that known-exploited catalogue, several linked to ransomware campaigns. A device left on an unsupported release is exploitable with no patch available, ever.
This is not a theoretical risk score. It is attackers using known working exploits against a device that will never be fixed.
How to check what you are running
Two minutes. Log into your FortiGate and look at the dashboard, or run this from the command line:
get sys status
You want the version number and the exact build. Then check it against this:
| Version | Status | What to do |
|---|---|---|
| 7.0 or older | Past end of support | Urgent. Already unpatched for over a year. |
| 7.2 | Ended 30 Sept 2026 | Plan the upgrade this month |
| 7.4 | Supported to Nov 2028 | Fine. Note maintenance releases stop May 2027. |
| 7.6 | Supported to Jan 2030 | Good position |
| 8.0 | Supported to Oct 2030 | Longest runway |
The trap nobody warns you about
Here is where a straightforward upgrade turns into an outage.
Fortinet has removed SSL VPN from the entry-level G-series models — the 50G, 70G, 90G and their variants. On the 70G it works on FortiOS 7.2, but support stops from 7.4.8 onward.
So if your staff connect remotely through the FortiClient SSL VPN, and you upgrade straight to a current release, remote working can stop on Monday morning. We have seen it happen.
| If you use | Before upgrading |
|---|---|
| SSL VPN for remote staff | Check whether your model keeps it on the target version. If not, plan the move to ZTNA as a separate step. |
| IPsec site-to-site tunnels | Unaffected on every model. No change needed. |
| FortiManager or FortiAnalyzer | Upgrade those first, in that order, then the FortiGate. Getting this backwards breaks management. |
| A Security Fabric | Check compatibility across every member before touching anything |
You cannot jump straight to the latest version
FortiOS upgrades follow a supported path. Going from 7.2 to a current release usually means several intermediate steps, each with its own reboot. Skipping steps is how configurations get corrupted.
Fortinet publishes an upgrade path tool for exactly this. Put in your model and current build, and it gives you the sequence.
A sane order of work
-
Find out what you have
Model, exact firmware build, licence expiry date, and whether the hardware itself is still current. All four matter.
-
Check the remote-access question first
Before anything else, establish whether SSL VPN is in use and whether your target version and model still support it. This decides the whole plan.
-
Back up the configuration
A full config backup before you start, and again between each step. Not optional.
-
Work out the upgrade path
Use Fortinet's upgrade path tool. Read the release notes for every intermediate version, not just the final one.
-
Schedule a maintenance window
Each step reboots the firewall. Evening or weekend, with the old config ready to restore.
-
Upgrade in order
FortiManager, then FortiAnalyzer, then the FortiGate. Test after each stage rather than at the end.
-
Watch it for a fortnight
New versions change defaults. Expect some false positives and tune them out rather than switching inspection off.
When upgrading is the wrong answer
Sometimes the firmware is not the real problem. Check the hardware too.
Through the first half of 2026, seven FortiGate F-series models reached End of Order — the 70F, 80F, 100F, 200F, 600F, 6300F and 6500F. End of Order is not End of Support, and those models remain supported into 2031. But if you are already planning downtime and budget, it is worth knowing where your hardware sits in its life cycle before you spend on it.
The G-series replacements deliver substantially higher inspection throughput than the F-series equivalents. If your current unit is already struggling with SSL inspection — or if someone switched inspection off to make the internet feel faster — replacing may cost less than upgrading twice.
One honest warning: mixing F-series and G-series units in a high-availability pair is supported, but it adds firmware and configuration-sync complications. Plan the pair together.
If you do nothing
The firewall keeps passing traffic. Nothing visibly breaks. That is exactly what makes this dangerous — there is no alarm, no outage, no prompt to act.
What changes is that the next serious vulnerability in that release will never be fixed on your device. And based on what happened to 7.0, the gap between end of support and an actively exploited flaw was about ten months.
Not sure what you are running?
Send us your FortiGate model and serial number and we will tell you your firmware status, licence expiry, where your hardware sits in its life cycle, and what the upgrade path looks like. Free, and no obligation to buy anything.
Questions we are getting this week
What happens to my FortiGate now that 7.2 is end of support?
It keeps working. It keeps passing traffic. What stops is fixes — Fortinet will not patch that release again, including for critical security vulnerabilities — and technical support is no longer available for it.
Which FortiOS version should I upgrade to?
7.4 is supported to November 2028, 7.6 to January 2030, and 8.0 to October 2030. The right target depends on your hardware model, your Security Fabric members and whether you need SSL VPN. Check the supported upgrade path for your specific model rather than going straight to the newest.
Will upgrading break our remote access?
It can. Fortinet removed SSL VPN from the entry-level G-series models — the 50G, 70G and 90G and their variants. On the 70G it works on 7.2 but loses support from 7.4.8. IPsec site-to-site tunnels are unaffected on every model. Check this before you plan anything else.
Can I upgrade straight from 7.2 to the latest version?
Usually not. FortiOS upgrades follow a supported path with intermediate steps, each requiring a reboot. Fortinet publishes an upgrade path tool that gives you the exact sequence for your model and build.
What order should I upgrade things in?
FortiManager first, then FortiAnalyzer, then the FortiGate. Doing it the other way round breaks management. Take a full configuration backup before each step.
Should I upgrade or replace the hardware?
It depends on the model's age and whether it is coping with inspection today. If inspection has been switched off to improve speed, or the unit is near the end of its life cycle, replacing can work out cheaper than upgrading now and replacing in two years.
Do you handle FortiGate upgrades in the UAE?
Yes. We are a Fortinet partner and we plan and run upgrades across all seven emirates and the wider GCC — including the config backup, the staged path, the out-of-hours window and the tuning afterwards.