FortiOS 7.2 ends on 30 September — your support ended back in March 2025
Your lifecycle sheet says 30 September 2026. The date that mattered was 31 March 2025. That is when FortiOS 7.2 left engineering support. Since then Fortinet has not been fixing ordinary bugs in that branch — only what qualifies as critical or as a PSIRT case. Plan around 30 September alone and you start the migration eighteen months late.
Fortinet publishes two end dates, not one
Most vendors give you one end-of-support date. Fortinet gives you two, eighteen months apart. End of Engineering Support (EoES) falls 36 months after the GA date of a branch. A “Must Fix” phase of another 18 months follows, and at its end sits End of Support (EOS) — that is the arithmetic in Fortinet’s lifecycle description.
What happens in those eighteen months is the point. Fortinet’s own TAC guidance says that once a branch is past EoES, a confirmed software problem will not be fixed there — the exception being critical issues and PSIRT vulnerabilities (source). The branch keeps running, but it is no longer repaired, only sealed. From EOS onwards even that stops: no ticket, no patch, no commitment.
Eight branches, two columns
| Branch | GA | EoES | EOS |
|---|---|---|---|
| 8.0 | 21/04/2026 | 21/04/2029 | 21/10/2030 |
| 7.6 | 25/07/2024 | 25/07/2028 | 25/01/2030 |
| 7.4 | 11/05/2023 | 11/05/2027 | 11/11/2028 |
| 7.2 | 31/03/2022 | 31/03/2025 | 30/09/2026 |
| 7.0 | 30/03/2021 | 30/03/2024 | 30/09/2025 |
| 6.4 | 31/03/2020 | 31/03/2023 | 30/09/2024 |
| 6.2 | 28/03/2019 | 28/03/2022 | 28/09/2023 |
| 6.0 | 29/03/2018 | 29/03/2021 | 29/09/2022 |
Four of the eight branches are already past EOS; 7.2 has 42 days left as of 19/08/2026. Two rows carry figures newer than they look: in March 2026 Fortinet extended 7.4 and 7.6 by a year each through bulletin CSB-260330-1 — 7.4 to EoES 11/05/2027 and EOS 11/11/2028, 7.6 to EoES 25/07/2028 and EOS 25/01/2030 (announcement). Anyone who pasted this table into a wiki a year ago is reading wrong numbers today. 7.2 got no such extension.
The device can upgrade itself — but yours cannot
Since FortiOS 7.4.8 and 7.6.4, a FortiGate upgrades itself to the latest patch of its current minor version in two situations: when the Firmware & General Updates (FMWR) licence is invalid, or when the minor version it runs has reached EoES (administration guide). It checks FortiGuard daily, and once a condition holds and a patch is out, it schedules the upgrade. You cannot cancel it. The documentation names exactly one lever: execute auto-upgrade delay-installation postpones the installation by a fixed seven days, an unlimited number of times — but it cannot be run on the day the update is scheduled for. The jump stays inside the minor version: 7.4.10 becomes the newest 7.4.x, never 7.6.x.
A device on 7.2 does none of this. The requirement starts at 7.4.8 and 7.6.4. The branch that would need the self-help most is precisely the one without it — 7.2 sits there until a person walks up to it. The mirror image is just as uncomfortable: run 7.4.8 or newer with a lapsed contract and your firewall may reboot on its own, followed by an email to the registered FortiCare account. Nobody agreed a maintenance window for that.
One command settles what applies to your box: execute auto-upgrade status reports Current Image Reached End of Life, the Support Contract Status and the scheduled window of a forced run, if there is one. Four states switch the automation off — a special build, membership in the Security Fabric, a connection to FortiManager, which even cancels a scheduled required upgrade, and the secondary of an HA pair, which gets the upgrade through the primary.
The LTS row is not an extension for you
In Fortinet’s lifecycle table, 7.2 is flagged Long Term Support with an Extended End of Support of 31/03/2028 (PSIRT policy note). That reads like eighteen free months. It is eighteen free months for customers holding an active FortiCare Elite contract; Essential and Premium are explicitly not eligible for LTS updates released after the standard EOS date (source). Fortinet adds that buying Elite after the fact to secure the extended period is problematic, and that by then there may be no upgrade path onto the LTS firmware at all (source). For most estates the date is simply 30 September 2026.
Why this weighs more on a firewall
patchletter records 15 entries for FortiOS from the CISA catalogue of known exploited vulnerabilitiesas of 19/08/2026 — flaws whose exploitation was observed, not merely imagined. Twelve carry CISA’s ransomware marker, three have been in the catalogue since 03/11/2021, and the most recent was added on 27/07/2026. Those entries apply to the product FortiOS, not to one branch; which versions are affected is stated in each Fortinet PSIRT advisory. The order of magnitude still says something. A device that has been getting security fixes only since March 2025, and none at all after October, sits in exactly the class of product attackers demonstrably keep walking through.
What to settle before 30 September
- Establish the facts.
get system statusgives version and build,diagnose test update infothe contract state. - Pull the upgrade path, do not guess it. Fortinet’s upgrade path tool lists the intermediate hops; skipping them can cost configuration, remote access or HA synchronisation.
- Check the contract before the jump. With an expired support contract, FortiOS allows higher patch levels within the same minor version only — 7.2.11 to 7.2.13 yes, 7.2 to 7.4 no (source).
- Separate the models that cannot follow. Some older platforms never got the newer branches. Fortinet’s own answer to that is not an exemption but the advice to replace the device with a compatible model (source). That is a procurement question, not a maintenance window.
One more thing follows from the forced upgrade: if the box may pull itself onto the latest patch, you want to know which patch that is before it tells you. patchletter tracks FortiOS releases on its FortiOS product page — tick the product and you get an email when a new version ships. The support cycles from the table above sit on that same page, the exploited vulnerabilities on the CVE page. Free, no account, one-click unsubscribe.
The honest limitation
Lifecycle dates are not constants of nature — the proof is in the table above, where 7.4 and 7.6 gained a year in March 2026. Whether 7.2 will be granted the same, nobody outside Fortinet knows; the bulletin named only the other two branches. Plan for 30 September and be pleased if it turns out otherwise. And note what patchletter does not do: it reports new releases, not end-of-support dates. The cycles are there to read, but no alarm goes off.
Cycle count and KEV figures from our own dataset as of 19/08/2026 — eight FortiOS branches, 15 entries in the CISA KEV catalogue, 12 of them with a ransomware marker. The EoES column comes from endoflife.date, retrieved 19/08/2026. Lifecycle definitions, forced-upgrade behaviour, LTS conditions and the extension for 7.4 and 7.6 come from Fortinet’s own documentation, linked above and retrieved 19/08/2026. Fortinet’s product lifecycle page remains authoritative.