endoflife.ai
EOL Checker Products EOL Watch Get Support

FortiOS 7.2 End of Support Is September 30, 2026 — and FortiOS 7.0 Already Showed What Comes After

Published: August 10, 2026  ·  EOL Watch — deadline coverage  ·  Dates verified against our tracked lifecycle data, which traces to Fortinet's published product life cycle policy — methodology

In 51 days, on September 30, 2026, FortiOS 7.2 reaches End of Support. If that date reads like the start of a countdown, it isn't — it's the end of one. The 7.2 train stopped receiving regular bug fixes sixteen months ago, when its engineering support ended on March 31, 2025. What September 30 removes is the last thing left: critical fixes. After that date, a FortiGate running 7.2 is a perimeter security appliance whose operating system will never change again, no matter what is found in it.

Normally an article like this would have to speculate about what "no more fixes" means in practice. On this product line, no speculation is needed. FortiOS 7.0 crossed the same line one year earlier — End of Support on September 30, 2025 — and within ten months it had an actively-exploited, CISA-KEV-listed vulnerability that Fortinet fixed only in supported trains, with migration as the only remediation offered for 7.0. That entry sits in our Exploited & Unpatchable feed today. It is the documented pattern for what End of Support means on this product, and 7.2 is 51 days from the same line.

What September 30, 2026 actually changes: FortiOS 7.2 has already been on critical-fixes-only status since March 31, 2025 — engineering support (regular maintenance releases and bug fixes) ended then, per the ~36-month mark in Fortinet's product life cycle policy. September 30, 2026 is the ~54-month End of Support mark: after it, no fixes of any kind — including critical and security fixes — and no technical support. The precedent from 7.0 shows how post-EOL issues are handled: Fortinet advisories list the end-of-life train as affected and offer "migrate to a fixed release" as the remediation.

The two-phase reality: 7.2's patch flow already narrowed in March 2025

Fortinet's lifecycle for FortiOS has two ends, and conflating them is how teams misjudge their exposure. Under Fortinet's published product life cycle policy, a release train gets roughly 36 months from release to End of Engineering Support — the end of regular maintenance releases — and roughly 54 months to End of Support, the end of everything. Between those two marks, a train is eligible for critical fixes only. (Fortinet's own lifecycle pages sit behind a support-portal login, which is why we mirror the dates in our tracked FortiOS lifecycle data, sourced from that policy.)

FortiOS 7.2 shipped on March 31, 2022 and has tracked that rhythm exactly: engineering support ended March 31, 2025, and End of Support lands September 30, 2026. So the question "is 7.2 still supported?" has had a narrower answer than most dashboards show for sixteen months already. A 7.2 estate has not been receiving regular bug fixes since March 2025 — only fixes Fortinet deems critical. September 30 doesn't start the degradation; it finishes it.

There is a second, sharper wrinkle, and it comes from Fortinet's own advisory data. For CVE-2025-68686 — the actively-exploited vulnerability covered in the next section — advisory FG-IR-25-934 lists all 7.2 versions as affected, and the fixed builds it names are in other trains: 7.6.2 and 7.4.7. The remediation offered is to migrate to a fixed release. In other words, for at least one KEV-listed issue, the practical remediation on 7.2 is already migration rather than a patch — while the train is still inside its supported window. That is what the last weeks of a release train's life look like on this product line.

Running FortiOS past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers FortiOS is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

The 7.0 precedent: exploited, past end of support, and no fix coming — ever

Our Exploited & Unpatchable feed tracks one specific, verifiable intersection: vulnerabilities in CISA's Known Exploited Vulnerabilities catalog — meaning CISA has evidence of active exploitation — that affect end-of-life versions which will never receive the fix. FortiOS is in it.

CVE-2025-68686 is a symlink-based persistence mechanism that survives patching — a post-exploitation weakness abused after a threat actor has already exploited a separate filesystem-level vulnerability. Its CVSS score is modest (5.9 per NVD; Fortinet rates it 5.3), and that is precisely what makes it instructive: its danger isn't a flashy remote-code-execution number, it's that an attacker who got in through an earlier hole keeps their access even after the original hole is patched. CISA added it to the KEV catalog on July 27, 2026, with a federal remediation deadline of August 10, 2026 — the day this article is published.

Per Fortinet's advisory FG-IR-25-934, the affected versions are FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, all 7.2, all 7.0, and all 6.4. The fixed builds are 7.6.2 and 7.4.7 — supported trains only. For 7.0 and 6.4, the advisory lists "all versions" as affected and gives exactly one remediation: migrate to a fixed release. No fixed build is or will be published for either branch — 7.0 reached End of Support on September 30, 2025, and 6.4 on September 30, 2024. That is why those two trains carry this CVE in our feed as permanently unpatchable.

Read the timeline the way an attacker would. FortiOS 7.0 reached End of Support on September 30, 2025. On July 27, 2026 — under ten months later — it had an actively-exploited, KEV-listed vulnerability that will never be fixed on that train. This is not a projection about FortiOS 7.2. It is the documented, cited record of what End of Support has meant on this exact product line, one train and one year ahead of 7.2. On September 30, 2026, 7.2 crosses the same line — and every issue found in it afterward gets the 7.0 treatment: listed as affected, fixed elsewhere, remediation "migrate."

The full entry — vulnerability details, affected statement, sources to CISA's KEV catalog, Fortinet's advisory, and NVD — is on the Exploited & Unpatchable page, with a free JSON feed at /exploited-and-unpatchable.json. Every entry is verified against the vendor's own advisory before it goes in; "unpatchable" means the vendor's documentation says so, not that we infer it.

Why a perimeter appliance is the worst category to run unsupported

Unsupported software is a risk everywhere, but the risk is not evenly distributed, and a perimeter firewall sits at the bad end of every axis that matters:

It is internet-facing by definition. An EOL database behind three network layers has some insulation while you plan. A FortiGate's job is to be the thing the internet touches first — its VPN portal and service interfaces are reachable attack surface by design. There is no "we'll firewall it off" mitigation, because it is the firewall.

It is credential-rich. The device terminates VPN sessions, holds local and integrated credentials, and mediates authentication for remote access. Compromising it doesn't just breach one box — it hands over the traffic and credentials of everyone who passes through it. CVE-2025-68686 is exactly this shape: the persistence technique preserved access to device files after patching.

The category has a long, public exploitation history. Network edge devices — Fortinet's among them — appear repeatedly in CISA's Known Exploited Vulnerabilities catalog and have been exploited at scale for years; that track record is why CISA's BOD 26-02 directive specifically orders federal agencies to get end-of-support devices off the network edge, and why our own feed is disproportionately populated by perimeter products. When a category is this actively hunted, "no more fixes" is not a paperwork status — it is a standing invitation with a widening window.

And nothing sits in front of it. Every other system in your estate has at least one compensating control between it and the internet. The perimeter appliance is the compensating control. When it can no longer be patched, there is no layer above it to lean on.

Every FortiOS version's dates

All dates from our tracked FortiOS lifecycle data, current as of the verification pass on August 10, 2026. Each version links to its lifecycle page with live status and risk score.

VersionStatusReleasedEngineering / maintenance support endedEnd of Support (EOL)
FortiOS 8.0SupportedApr 21, 2026Apr 21, 2029Oct 21, 2030
FortiOS 7.6SupportedJul 25, 2024Jul 25, 2028Jan 25, 2030
FortiOS 7.4SupportedMay 11, 2023May 11, 2027Nov 11, 2028
FortiOS 7.2WarningMar 31, 2022Mar 31, 2025Sep 30, 2026
FortiOS 7.0EOLMar 30, 2021Mar 30, 2024Sep 30, 2025
FortiOS 6.4EOLMar 31, 2020Mar 31, 2023Sep 30, 2024
FortiOS 6.2EOLMar 28, 2019Mar 28, 2022Sep 28, 2023
FortiOS 6.0EOLMar 29, 2018Mar 29, 2021Sep 29, 2022

"Engineering / maintenance support ended" is the End of Engineering Support milestone in Fortinet's product life cycle policy — after it, a train receives critical fixes only; after End of Support, nothing. The dates follow the policy's ~36-month and ~54-month rhythm from each train's release. Fortinet publishes its lifecycle table behind a support-portal login; our mirrored dates are re-verified nightly against the upstream endoflife.date dataset, whose cited sources are Fortinet's product life cycle page and life cycle policy document.

The decision fork: 7.4, 7.6, or 8.0

There is no "stay on 7.2 with mitigations" branch worth writing — this is a perimeter device, and the 7.0 record above shows what the unsupported branch looks like within a year. The real decision is which supported train to land on, and it is a trade between maturity and runway:

FortiOS 7.4 — the longest-established current train. Released May 2023, it is the most mature of the three, with the longest field history — the conservative pick for change-averse environments. The honest caveat is its clock: engineering support ends May 11, 2027 and End of Support is November 11, 2028, so choosing 7.4 means planning the next upgrade sooner. If you go this way, land on 7.4.7 or later — 7.4.7 is one of the two fixed builds for CVE-2025-68686.

FortiOS 7.6 — the middle path. Released July 2024, supported to January 25, 2030 — over a year more runway than 7.4, with two years of field maturity behind it. The fixed build for CVE-2025-68686 on this train is 7.6.2 or later.

FortiOS 8.0 — the longest runway. The newest train, released April 21, 2026, with End of Support October 21, 2030. It resets the lifecycle clock furthest, at the cost of being the least field-proven — a reasonable target for estates that upgrade rarely and want the longest gap before doing this again.

The hardware caveat that gates all three: not every FortiGate model supports every FortiOS train. Older FortiGate hardware may not be able to run the newer releases at all — meaning for some fleets, the 7.2 software deadline is actually a hardware refresh decision in disguise. Before committing to a target train, check Fortinet's supported upgrade paths and your specific models' compatibility; an upgrade plan that ignores this gets discovered by its exceptions.

We track FortiOS and 480+ other products against vendor-verified datesevery FortiOS version with live status, check any version in seconds, or see what else hits end of life this quarter.

What to do about it

FortiOS currently carries an EOL Risk Score™ of 40/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the FortiOS lifecycle page.

The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination.

Frequently Asked Questions

When exactly does FortiOS 7.2 support end?

Two dates matter, and one of them has already passed. End of Engineering Support for FortiOS 7.2 was March 31, 2025 — since then the train has been eligible for critical fixes only, with no regular maintenance releases. End of Support is September 30, 2026 — after that date, no fixes of any kind, including critical ones. The dates follow Fortinet's published product life cycle policy rhythm: roughly 36 months from release (7.2 shipped March 31, 2022) to end of engineering support, and roughly 54 months to end of support.

Is FortiOS 7.2 still getting security patches today?

Only critical fixes — and not always even those. Since engineering support ended on March 31, 2025, the 7.2 train has been on critical-fixes-only status. But the practical limit is already visible: Fortinet's advisory FG-IR-25-934 for CVE-2025-68686 — added to CISA's Known Exploited Vulnerabilities catalog on July 27, 2026 — lists all 7.2 versions as affected and names fixed builds only in newer trains (7.6.2 and 7.4.7), with "migrate to a fixed release" as the remediation. So for at least one actively-exploited, KEV-listed issue, the answer on 7.2 is already migration rather than a patch — while 7.2 is still technically supported.

What happens if I keep running FortiOS 7.2 after September 30, 2026?

The precedent is documented on this product line, one train back. FortiOS 7.0 reached End of Support on September 30, 2025. On July 27, 2026 — under ten months later — CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog. Fortinet's advisory lists all 7.0 versions as affected, ships the fix only in supported trains, and gives migration as the only remediation for the end-of-life branches — 7.0 will never receive that fix. Any comparable issue found in 7.2 after September 30, 2026 gets the same treatment. And this is a perimeter security appliance: internet-facing by definition, holding VPN credentials and sessions, sitting in front of every other control you have.

Which FortiOS version should I upgrade to — 7.4, 7.6, or 8.0?

All three are currently supported, per our tracked lifecycle data. FortiOS 7.4 is the longest-established current train (released May 2023) — engineering support to May 11, 2027 and End of Support November 11, 2028, so it is the most mature target but has the shortest runway. FortiOS 7.6 runs to January 25, 2030, and 8.0 — the newest train, released April 21, 2026 — to October 21, 2030. One hardware caveat before choosing: not every FortiGate model supports every FortiOS train, and older models may not be able to run the newer releases — check Fortinet's supported upgrade paths and your model's compatibility before committing. Whichever train you land on, note that the fixed builds for CVE-2025-68686 are 7.6.2 and 7.4.7 — land on or above them.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)