Fortinet white logo
Fortinet white logo

Existing known issues

Existing known issues

The following issues have been identified in a previous version of FortiClient (macOS) and remain in FortiClient (macOS) 7.2.13.

Application Firewall

Bug ID

Description

834839

Web Filter does not block traffic when proxy mode and Application Firewall are disabled.

948718

Block count for Application Firewall is not accurate.

Avatar and social login information

Bug ID

Description

777013

Avatar, whether changed or existing, does not show on FortiAnalyzer.

857857

Avatar page goes blank if user logs in with LinkedIn account.

954273

After FortiClient upgrades through script, avatar page does not load properly and shows a blank page.

Deployment and installers

Bug ID

Description

882705 EMS deployment fails if endpoint reboots during deployment package installation process.
975804 FortiClientUninstaller is damaged error occurs during FortiClient (macOS) deployment.

Endpoint control

Bug ID

Description

949324

Re-authentication error for verified registered FortiClient endpoints with the SAML or Entra ID user verification type when User Verification Period is enabled in EMS.

958511

FortiClient (macOS) does not support Microsoft Entra ID verification when connecting to EMS.

Endpoint management

Bug ID

Description

891264 EMS creates duplicate records for domain-joined Ubuntu endpoints.
1106089 FortiClient fails to open with syntax error prompt if compliance.json file is empty.

Endpoint policy and profile

Bug ID

Description

906951 GUI does not reflect profile changes unless user manually restarts the FortiClient (macOS) console.

FSSOMA

Bug ID

Description

956538

FortiClient (macOS) does not support multiple FortiAuthenticator server addresses.

GUI

Bug ID

Description

786779

About page version infomation is cut off when displaying with copyright information.

857148

GUI shows duplicate FortiClient consoles.

954876

Backup Comments option does not work.

967169

GUI is stuck on blank screen.

Installation and upgrade

Bug ID

Description

828781 FortiClient (macOS) behaves inconsistently when uninstalling it through commands in terminal and the FortiClientUninstaller GUI tool.

929219

FortiClient is upgradable from full to free version.

951945

Uninstaller shows Install Now prompt instead of Remove now.

955448

Manual upgrade from 7.2.0 removes manually added VPN tunnels.

License

Bug ID

Description

889767 License expiration shows unwanted +0000 at end of warning message.

Logs

Bug ID

Description

711763

FortiClient does not point to usfgd1.fortigate.com for EMS web profile setting:Location-US | Server-Fortiguard (Legacy).

951917 The device MAC address field for FortiClient (macOS)-related events under FortiAnalyzer shows 00:00:00:00:00:00 instead of device MAC address.
1002118 fctlogupload causes CPU to spike to 100%.

Malware Protection and Sandbox

Bug ID

Description

551282 Sandbox exception for trusted sources does not work and FortiClient (macOS) uploads files sourced from Apple Inc.
719920 FortiClient cannot submit files downloaded from Thunderbird to FortiClient Cloud Sandbox (PaaS).

855555

Enabling real-time protection and setting <block_removable_media> to 1 causes FortiClient (macOS) to fail to block a USB device.

949187 Cloud Sandbox fails to work and treats EICAR file as clean.

Real-time protection

Bug ID

Description

855570 RTP scans files regardless of the maximum file size setting for scanning files.
949258 GUI shows no events under Realtime Protection events.
951380 RTP creates folder when Word and Excel files are saved on network shared drive (NAS).

Remote Access

Bug ID

Description

800529

GUI has issue with Settings > VPN Options > Do not Warn Invalid Server Certificate.

818359 FortiClient (macOS) does not instantly clear saved password when user deselects Save Password for VPN tunnel.
977725 FortiClient split tunnel has limitation.

Remote Access - IPsec VPN

Bug ID

Description

720236 FortiClient does not support DH groups 19-21.
894027 FortiClient on macOS Ventura system proxy with PAC does not work with IPsec VPN but works with SSL VPN.
948566 Enable Local LAN does not work as expected.
952987 FortiClient (macOS) does not clear IPsec VPN tunnel saved password if connection fails due to wrong credentials.
954632 IPsec VPN fails to update password in keychain store when trying to renew expired AD password with autoconnect enabled.
976852 IPsec VPN redundancy based on ping speed or TCP RTT sorting method does not work.
978270 DNS fails to apply to the IPsec VPN tunnel interface after disabling <mode_config> in IPsec VPN IKEv1 and setting manual mode.

Remote Access - SSL VPN

Bug ID

Description

866711

SSL VPN with SAML and FIDO2 authentication does not work with built-in browser.

978147 DHCP Option 12 - hostname needed if using SSL VPN with external DHCP servers.
978792 GUI is stuck in VPN connecting page when VPN connected successfully.
985277

When connected to a split tunnel VPN, FortiClient (macOS) does not connect to local LAN.

Software Inventory

Bug ID

Description

860954

Sending software inventory list or updates to EMS does not happen in real time.

Third-party compatibility

Bug ID

Description

961542

Conflict occurs between FortiClient and Microsoft Defender due to the system processes used in overlapping real-time protection features.

Workaround: enable passive mode on Microsoft Defender.

1085782 Cisco Umbrella does not work when ZTNA is enabled.

Vulnerability Scan

Bug ID

Description

771833 FortiClient tags endpoint as vulnerable when EMS administrator has enabled Exclude Application Vulnerabilities Requiring Manual Update from Vulnerability.

Web Filter and plugin

Bug ID

Description

1255625 FortiClient (macOS) 7.2.13 fails to recognize the newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers, which results in failed communication for the following updates:
  • Web Filter rating
  • Video Filter rating
  • Split VPN using ISDB
  • Signature and engine updates

See CSB-260303-1 for more information.

873803 In-browser message does not show after switching device user without system reboot.
898303 Web Filter does not work when administrator pushes extensions through Jamf in mobile device management platform.
955529 Teams and other applications that use video crash and fail to work.
998541 Web Filter on Only when Endpoint is Off-Fabric does not work properly.
1022664 When FortiClient (macOS) blocks all Web Filter categories, exclusions do not work properly.

Security tags

Bug ID

Description

794385 FortiClient (macOS) detects third party antivirus tag.

ZTNA connection rules

Bug ID

Description

807827

FortiClient is missing external browser support for SAML authentication for ZTNA.

961800

When ZTNA is enabled, pfctl rules affect DNS traffic.

994025 ZTNA fails to work when no port number is specified on the destination rule.

1155036

ZTNA TCP forwarding SAML session starts redirect with TCP fwf path.

ZTNA TCP/UDP forwarding

Bug ID

Description

853281 FortiClient (macOS) does not show the inline CASB database signatures on the About page.

1094278

ZTNA fails to process when destination rule is configured with port range.

Existing known issues

Existing known issues

The following issues have been identified in a previous version of FortiClient (macOS) and remain in FortiClient (macOS) 7.2.13.

Application Firewall

Bug ID

Description

834839

Web Filter does not block traffic when proxy mode and Application Firewall are disabled.

948718

Block count for Application Firewall is not accurate.

Avatar and social login information

Bug ID

Description

777013

Avatar, whether changed or existing, does not show on FortiAnalyzer.

857857

Avatar page goes blank if user logs in with LinkedIn account.

954273

After FortiClient upgrades through script, avatar page does not load properly and shows a blank page.

Deployment and installers

Bug ID

Description

882705 EMS deployment fails if endpoint reboots during deployment package installation process.
975804 FortiClientUninstaller is damaged error occurs during FortiClient (macOS) deployment.

Endpoint control

Bug ID

Description

949324

Re-authentication error for verified registered FortiClient endpoints with the SAML or Entra ID user verification type when User Verification Period is enabled in EMS.

958511

FortiClient (macOS) does not support Microsoft Entra ID verification when connecting to EMS.

Endpoint management

Bug ID

Description

891264 EMS creates duplicate records for domain-joined Ubuntu endpoints.
1106089 FortiClient fails to open with syntax error prompt if compliance.json file is empty.

Endpoint policy and profile

Bug ID

Description

906951 GUI does not reflect profile changes unless user manually restarts the FortiClient (macOS) console.

FSSOMA

Bug ID

Description

956538

FortiClient (macOS) does not support multiple FortiAuthenticator server addresses.

GUI

Bug ID

Description

786779

About page version infomation is cut off when displaying with copyright information.

857148

GUI shows duplicate FortiClient consoles.

954876

Backup Comments option does not work.

967169

GUI is stuck on blank screen.

Installation and upgrade

Bug ID

Description

828781 FortiClient (macOS) behaves inconsistently when uninstalling it through commands in terminal and the FortiClientUninstaller GUI tool.

929219

FortiClient is upgradable from full to free version.

951945

Uninstaller shows Install Now prompt instead of Remove now.

955448

Manual upgrade from 7.2.0 removes manually added VPN tunnels.

License

Bug ID

Description

889767 License expiration shows unwanted +0000 at end of warning message.

Logs

Bug ID

Description

711763

FortiClient does not point to usfgd1.fortigate.com for EMS web profile setting:Location-US | Server-Fortiguard (Legacy).

951917 The device MAC address field for FortiClient (macOS)-related events under FortiAnalyzer shows 00:00:00:00:00:00 instead of device MAC address.
1002118 fctlogupload causes CPU to spike to 100%.

Malware Protection and Sandbox

Bug ID

Description

551282 Sandbox exception for trusted sources does not work and FortiClient (macOS) uploads files sourced from Apple Inc.
719920 FortiClient cannot submit files downloaded from Thunderbird to FortiClient Cloud Sandbox (PaaS).

855555

Enabling real-time protection and setting <block_removable_media> to 1 causes FortiClient (macOS) to fail to block a USB device.

949187 Cloud Sandbox fails to work and treats EICAR file as clean.

Real-time protection

Bug ID

Description

855570 RTP scans files regardless of the maximum file size setting for scanning files.
949258 GUI shows no events under Realtime Protection events.
951380 RTP creates folder when Word and Excel files are saved on network shared drive (NAS).

Remote Access

Bug ID

Description

800529

GUI has issue with Settings > VPN Options > Do not Warn Invalid Server Certificate.

818359 FortiClient (macOS) does not instantly clear saved password when user deselects Save Password for VPN tunnel.
977725 FortiClient split tunnel has limitation.

Remote Access - IPsec VPN

Bug ID

Description

720236 FortiClient does not support DH groups 19-21.
894027 FortiClient on macOS Ventura system proxy with PAC does not work with IPsec VPN but works with SSL VPN.
948566 Enable Local LAN does not work as expected.
952987 FortiClient (macOS) does not clear IPsec VPN tunnel saved password if connection fails due to wrong credentials.
954632 IPsec VPN fails to update password in keychain store when trying to renew expired AD password with autoconnect enabled.
976852 IPsec VPN redundancy based on ping speed or TCP RTT sorting method does not work.
978270 DNS fails to apply to the IPsec VPN tunnel interface after disabling <mode_config> in IPsec VPN IKEv1 and setting manual mode.

Remote Access - SSL VPN

Bug ID

Description

866711

SSL VPN with SAML and FIDO2 authentication does not work with built-in browser.

978147 DHCP Option 12 - hostname needed if using SSL VPN with external DHCP servers.
978792 GUI is stuck in VPN connecting page when VPN connected successfully.
985277

When connected to a split tunnel VPN, FortiClient (macOS) does not connect to local LAN.

Software Inventory

Bug ID

Description

860954

Sending software inventory list or updates to EMS does not happen in real time.

Third-party compatibility

Bug ID

Description

961542

Conflict occurs between FortiClient and Microsoft Defender due to the system processes used in overlapping real-time protection features.

Workaround: enable passive mode on Microsoft Defender.

1085782 Cisco Umbrella does not work when ZTNA is enabled.

Vulnerability Scan

Bug ID

Description

771833 FortiClient tags endpoint as vulnerable when EMS administrator has enabled Exclude Application Vulnerabilities Requiring Manual Update from Vulnerability.

Web Filter and plugin

Bug ID

Description

1255625 FortiClient (macOS) 7.2.13 fails to recognize the newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers, which results in failed communication for the following updates:
  • Web Filter rating
  • Video Filter rating
  • Split VPN using ISDB
  • Signature and engine updates

See CSB-260303-1 for more information.

873803 In-browser message does not show after switching device user without system reboot.
898303 Web Filter does not work when administrator pushes extensions through Jamf in mobile device management platform.
955529 Teams and other applications that use video crash and fail to work.
998541 Web Filter on Only when Endpoint is Off-Fabric does not work properly.
1022664 When FortiClient (macOS) blocks all Web Filter categories, exclusions do not work properly.

Security tags

Bug ID

Description

794385 FortiClient (macOS) detects third party antivirus tag.

ZTNA connection rules

Bug ID

Description

807827

FortiClient is missing external browser support for SAML authentication for ZTNA.

961800

When ZTNA is enabled, pfctl rules affect DNS traffic.

994025 ZTNA fails to work when no port number is specified on the destination rule.

1155036

ZTNA TCP forwarding SAML session starts redirect with TCP fwf path.

ZTNA TCP/UDP forwarding

Bug ID

Description

853281 FortiClient (macOS) does not show the inline CASB database signatures on the About page.

1094278

ZTNA fails to process when destination rule is configured with port range.