Network Security · H7 Labs · UAE

FortiOS 7.2 reached end of support on 30 September. If your firewall is still on it, read this.

No more fixes. No more support. Not even for critical security vulnerabilities. Here is what that actually means, and what to do about it this month.

On 30 September 2026, FortiOS 7.2 reached End of Support. That is the end of the line — not a warning, not a deprecation notice. After this date Fortinet provides no fixes of any kind for that release, including critical and security fixes, and no technical support.

If your FortiGate is running 7.2, it is now a permanently unpatched device sitting at the edge of your network.

Regular maintenance for 7.2 actually stopped on 31 March 2025. It has been on critical fixes only for eighteen months. Most organisations we speak to did not know that either.

Why this matters more than a normal firmware update

We know exactly how this plays out, because it already happened once.

FortiOS 7.0 reached End of Support on 30 September 2025. Within ten months, an actively exploited vulnerability appeared in it — serious enough to be listed in the US cybersecurity agency's known-exploited catalogue. Fortinet fixed it in supported releases only. For anyone still on 7.0, the only remedy offered was migration.

There are already four FortiOS vulnerabilities in that known-exploited catalogue, several linked to ransomware campaigns. A device left on an unsupported release is exploitable with no patch available, ever.

This is not a theoretical risk score. It is attackers using known working exploits against a device that will never be fixed.

How to check what you are running

Two minutes. Log into your FortiGate and look at the dashboard, or run this from the command line:

get sys status

You want the version number and the exact build. Then check it against this:

VersionStatusWhat to do
7.0 or olderPast end of supportUrgent. Already unpatched for over a year.
7.2Ended 30 Sept 2026Plan the upgrade this month
7.4Supported to Nov 2028Fine. Note maintenance releases stop May 2027.
7.6Supported to Jan 2030Good position
8.0Supported to Oct 2030Longest runway

The trap nobody warns you about

Here is where a straightforward upgrade turns into an outage.

Fortinet has removed SSL VPN from the entry-level G-series models — the 50G, 70G, 90G and their variants. On the 70G it works on FortiOS 7.2, but support stops from 7.4.8 onward.

So if your staff connect remotely through the FortiClient SSL VPN, and you upgrade straight to a current release, remote working can stop on Monday morning. We have seen it happen.

If you useBefore upgrading
SSL VPN for remote staffCheck whether your model keeps it on the target version. If not, plan the move to ZTNA as a separate step.
IPsec site-to-site tunnelsUnaffected on every model. No change needed.
FortiManager or FortiAnalyzerUpgrade those first, in that order, then the FortiGate. Getting this backwards breaks management.
A Security FabricCheck compatibility across every member before touching anything

You cannot jump straight to the latest version

FortiOS upgrades follow a supported path. Going from 7.2 to a current release usually means several intermediate steps, each with its own reboot. Skipping steps is how configurations get corrupted.

Fortinet publishes an upgrade path tool for exactly this. Put in your model and current build, and it gives you the sequence.

A sane order of work

  1. Find out what you have

    Model, exact firmware build, licence expiry date, and whether the hardware itself is still current. All four matter.

  2. Check the remote-access question first

    Before anything else, establish whether SSL VPN is in use and whether your target version and model still support it. This decides the whole plan.

  3. Back up the configuration

    A full config backup before you start, and again between each step. Not optional.

  4. Work out the upgrade path

    Use Fortinet's upgrade path tool. Read the release notes for every intermediate version, not just the final one.

  5. Schedule a maintenance window

    Each step reboots the firewall. Evening or weekend, with the old config ready to restore.

  6. Upgrade in order

    FortiManager, then FortiAnalyzer, then the FortiGate. Test after each stage rather than at the end.

  7. Watch it for a fortnight

    New versions change defaults. Expect some false positives and tune them out rather than switching inspection off.

When upgrading is the wrong answer

Sometimes the firmware is not the real problem. Check the hardware too.

Through the first half of 2026, seven FortiGate F-series models reached End of Order — the 70F, 80F, 100F, 200F, 600F, 6300F and 6500F. End of Order is not End of Support, and those models remain supported into 2031. But if you are already planning downtime and budget, it is worth knowing where your hardware sits in its life cycle before you spend on it.

The G-series replacements deliver substantially higher inspection throughput than the F-series equivalents. If your current unit is already struggling with SSL inspection — or if someone switched inspection off to make the internet feel faster — replacing may cost less than upgrading twice.

One honest warning: mixing F-series and G-series units in a high-availability pair is supported, but it adds firmware and configuration-sync complications. Plan the pair together.

If you do nothing

The firewall keeps passing traffic. Nothing visibly breaks. That is exactly what makes this dangerous — there is no alarm, no outage, no prompt to act.

What changes is that the next serious vulnerability in that release will never be fixed on your device. And based on what happened to 7.0, the gap between end of support and an actively exploited flaw was about ten months.

Not sure what you are running?

Send us your FortiGate model and serial number and we will tell you your firmware status, licence expiry, where your hardware sits in its life cycle, and what the upgrade path looks like. Free, and no obligation to buy anything.

Questions we are getting this week

What happens to my FortiGate now that 7.2 is end of support?

It keeps working. It keeps passing traffic. What stops is fixes — Fortinet will not patch that release again, including for critical security vulnerabilities — and technical support is no longer available for it.

Which FortiOS version should I upgrade to?

7.4 is supported to November 2028, 7.6 to January 2030, and 8.0 to October 2030. The right target depends on your hardware model, your Security Fabric members and whether you need SSL VPN. Check the supported upgrade path for your specific model rather than going straight to the newest.

Will upgrading break our remote access?

It can. Fortinet removed SSL VPN from the entry-level G-series models — the 50G, 70G and 90G and their variants. On the 70G it works on 7.2 but loses support from 7.4.8. IPsec site-to-site tunnels are unaffected on every model. Check this before you plan anything else.

Can I upgrade straight from 7.2 to the latest version?

Usually not. FortiOS upgrades follow a supported path with intermediate steps, each requiring a reboot. Fortinet publishes an upgrade path tool that gives you the exact sequence for your model and build.

What order should I upgrade things in?

FortiManager first, then FortiAnalyzer, then the FortiGate. Doing it the other way round breaks management. Take a full configuration backup before each step.

Should I upgrade or replace the hardware?

It depends on the model's age and whether it is coping with inspection today. If inspection has been switched off to improve speed, or the unit is near the end of its life cycle, replacing can work out cheaper than upgrading now and replacing in two years.

Do you handle FortiGate upgrades in the UAE?

Yes. We are a Fortinet partner and we plan and run upgrades across all seven emirates and the wider GCC — including the config backup, the staged path, the out-of-hours window and the tuning afterwards.