Synced 16 Jun 2026 15:24 UTC Account
← All patching guides

How to patch FortiGate (FortiOS)

Fortinet · Network / Security · 6 steps · Fortinet FortiOS security status → · updated June 2026

FortiGate firewalls run FortiOS, and upgrades usually require following a supported upgrade path — you often cannot jump straight to the newest release. Always back up the config first, because a firewall is a single point of failure.

18
actively exploited (KEV)
270
tracked CVEs
latest supported

Fortinet FortiOS has 18 actively-exploited vulnerabilities on the CISA KEV list — patching is urgent.

Check your current version first

Before you patch, record what you're running (FortiGate CLI):

get system status

Or paste your version into the checker for an instant verdict.

Step by step

1
Check current firmware

Run get system status (or System → Firmware in the GUI) to record your model and FortiOS version/build.

2
Plan the supported upgrade path

FortiOS frequently requires stepping through intermediate versions. Use the Fortinet Upgrade Path tool to map the exact sequence — do not skip major versions.

3
Back up the configuration

Save a full config backup (System → Configuration → Backup, or execute backup config). If anything goes wrong you can restore in minutes.

4
Download firmware for your exact model

Get the firmware image matching your specific model from the Fortinet Support portal — images are model-specific.

5
Upgrade and reboot

Upload via System → Firmware (GUI) or execute restore image (CLI). The unit reboots automatically. Follow the planned path one hop at a time.

6
Verify and re-test

Confirm the new version with get system status, then verify policies, VPNs and connectivity still work.

Watch out for:
  • Never skip the supported upgrade path — jumping versions can corrupt the config.
  • Schedule a window: the firewall reboots during the upgrade and drops traffic briefly.

Official sources

Don't patch blind. Fortinet FortiOS has 18 actively-exploited vulnerabilities on the CISA KEV list — patching is urgent. See exactly which versions are safe and what you're exposed to.

Fortinet FortiOS security status →

Stay ahead of the next one

Frequently asked questions

What is the latest version of Fortinet FortiOS?

Check the current supported Fortinet FortiOS release on its product page or the official vendor advisory, then patch to it.

How do I check which version of Fortinet FortiOS I am running?

Use: get system status (FortiGate CLI). Record the result before and after patching to confirm the update applied.

Is Fortinet FortiOS being actively exploited right now?

Yes — 18 Fortinet FortiOS vulnerabilities are on the CISA Known Exploited Vulnerabilities (KEV) list, so attackers are using them in the wild. Patch promptly. See the exploitation radar.

How do I patch Fortinet FortiOS safely without breaking production?

Always test in a non-production environment first, take a backup or snapshot, follow the official vendor advisory, and have a tested rollback. Patch one node at a time for clustered or high-availability setups.

Patch steps are general, well-established guidance for Fortinet FortiOS — always test in a non-production environment first and follow the official Fortinet advisory for your exact version. IsItPatched is independent and not affiliated with Fortinet; this is not a substitute for vendor documentation. See our disclaimer.

← All patching guides · Security guides →