FortiOS (FortiGate)

Fortinet · current 8.0

The current version of FortiOS (FortiGate) is 8.0 (as of 08/07/2026). patchletter checks the official source daily and emails you every new release.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.

  • CVE-2018-13379Fortinet FortiOS SSL VPN Path Traversal VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2020-12812Fortinet FortiOS SSL VPN Improper Authentication VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2022-42475Fortinet FortiOS Heap-Based Buffer Overflow VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 3 Jan 23

  • CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 4 Jul 23

  • CVE-2024-21762Fortinet FortiOS Out-of-Bound Write VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 16 Feb 24

  • CVE-2024-55591Fortinet FortiOS and FortiProxy Authentication Bypass VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 21 Jan 25

  • CVE-2025-24472Fortinet FortiOS and FortiProxy Authentication Bypass VulnerabilityRansomware

    8.1 high · over the network, without login · CISA deadline was 8 Apr 25

  • CVE-2018-13382Fortinet FortiOS and FortiProxy Improper AuthorizationRansomware

    7.5 high · over the network, without login · CISA deadline was 10 Jul 22

  • CVE-2019-5591Fortinet FortiOS Default Configuration VulnerabilityRansomware

    6.5 medium · from the local network, without login · CISA deadline was 3 May 22

  • CVE-2018-13383Fortinet FortiOS and FortiProxy Out-of-bounds WriteRansomware

    6.5 medium · over the network, without login, needs user action · CISA deadline was 10 Jul 22

  • CVE-2019-6693Fortinet FortiOS Use of Hard-Coded Credentials VulnerabilityRansomware

    6.5 medium · over the network, with a basic account · CISA deadline was 16 Jul 25

  • CVE-2018-13374Fortinet FortiOS and FortiADC Improper Access Control VulnerabilityRansomware

    4.3 medium · over the network, with a basic account · CISA deadline was 29 Sept 22

  • CVE-2021-44168Fortinet FortiOS Arbitrary File Download

    7.8 high · locally only, with a basic account · CISA deadline was 24 Dec 21

  • CVE-2022-41328Fortinet FortiOS Path Traversal Vulnerability

    7.1 high · locally only, with a basic account · CISA deadline was 4 Apr 23

  • CVE-2025-68686Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    5.9 medium · over the network, without login · CISA deadline was 10 Aug

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

FortiOS (FortiGate) at a glance

FortiOS is the operating system on Fortinet's FortiGate firewalls, one of the most widespread enterprise perimeter platforms. Fortinet ships FortiOS releases across several branches plus security advisories — and FortiGate devices have repeatedly been the focus of actively exploited vulnerabilities, so patching here is not optional.

For admins the essentials: never expose the management or SSL-VPN interface to the WAN unprotected, and apply security advisories promptly. Pick the right FortiOS branch per model, take a config backup before upgrading, and follow the documented upgrade path (don't skip too many versions). On HA pairs mind the order; after upgrading, verify VPN tunnels and policies. Subscribe to Fortinet's PSIRT advisories — patchletter flags new FortiOS builds so nothing critical slips.

Support cycles (endoflife.date)

CycleLatest versionStatus
8.0EOL 21 Oct 30
7.6EOL 25 Jan 30
7.4EOL 11 Nov 28
7.2EOL in 35 days
7.0End of Life
6.4End of Life
6.2End of Life
6.0End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
8.0STABLE08/07/2026

Frequently asked questions

What is the latest version of FortiOS (FortiGate)?
FortiOS (FortiGate) 8.0, released 08/07/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the FortiOS (FortiGate) release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new FortiOS (FortiGate) updates?
Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.

Never miss a FortiOS (FortiGate) update

We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.

Watch FortiOS (FortiGate)

Embed this badge

Shows the current FortiOS (FortiGate) version and updates itself. Free to use, no account needed.

FortiOS (FortiGate) badge
[![FortiOS (FortiGate)](https://patchletter.com/badge/fortios.svg)](https://patchletter.com/en/software/fortios)
https://patchletter.com/badge/fortios.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Firewalls & Security