Special notices
FortiClient (Windows) 7.4.3 free VPN-only agent online installer update
The FortiClient (Windows) 7.4.3 free VPN-only agent online installer was updated on April 15, 2026 to address the following vulnerability:
|
Bug ID |
Description |
|---|---|
|
1188355 |
This issue does not affect users who have the FortiClient (Windows) 7.4.3 free VPN-only agent installed and running. It only affects those who have downloaded the FortiClient (Windows) 7.4.3 free VPN-only agent online installer before but have not installed it yet or have uninstalled it after initial installation. If you are affected, you must download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com before installing it. To verify the downloaded installer is the correct version, right-click the installer, select Properties, and make sure the version is 7.4.3.4799 in the Details tab.
FortiClient (Windows) 7.4.3 free VPN-only agent re-release
The FortiClient (Windows) 7.4.3 free VPN-only agent was re-released on March 20, 2026 to address the following vulnerabilities and issues:
|
Bug ID |
Description |
|---|---|
|
1129740 |
|
|
1147064 |
|
|
1188354 |
CVE-2025-66535 |
|
1193312 |
|
| 959868 | CVE-2025-54660 |
| 1147064 | CVE-2025-47761 |
|
1250474 |
|
|
1255625 |
FortiClient (Windows) fails to recognize the newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers. |
|
1257484 |
FortiClient (Windows) inadvertently may poll FortiGuard for the Internet Service database (ISDB) every six hours. |
To install the new version, download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com and double-click it to complete the installation. To verify the installation is successful, make sure the FortiClient version is 7.4.3.4726 in the About page of the FortiClient GUI.
FortiClient (Windows) 7.4.3 GA hotfix 1
FortiClient (Windows) 7.4.3 GA hotfix 1 (7.4.3.1790.1.8758) was released on December 11, 2025 to address the following vulnerabilities:
|
Bug ID |
Description |
|---|---|
|
1129740 |
|
|
1147064 |
|
|
1188354 |
CVE-2025-66535 |
To install the hotfix from EMS, collect the EMS serial numbers and contact Fortinet Support.
To install the hotfix locally:
-
Download the
FortiClientTools_7.4.3.8758.zipfile from the Fortinet Support website. -
Unzip the file and copy the
FortiClientTools_7.4.3.8758\SupportUtils\hotfix.exefile to theDownloadsfolder. -
Shutdown FortiClient and run the following installation command in PowerShell:
C:\Users\ftntt\Downloads>cmd /k hotfix.exe
-
When the Hotfix 7.4.3.8758 is now installed message is displayed, verify the following:
-
The
C:\windows\system32\driver\fortips_74.sysfile has been updated (check modification date) -
The
C:\Program Files\Fortinet\FortiClient\resources\app.asarfile has been updated (check modification date) -
The FortiClient version is 7.4.3 hotfix 1.8758 in the About page of the FortiClient GUI.
-
FortiClient (Windows) 7.4.3 free VPN-only agent GA update 1
FortiClient (Windows) 7.4.3 free VPN-only agent GA update 1 (7.4.3.1790.1.8758) was released on December 11, 2025 to address the following vulnerabilities:
|
Bug ID |
Description |
|---|---|
|
1129740 |
|
|
1147064 |
|
|
1188354 |
CVE-2025-66535 |
To install the update, download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com and double-click it to complete the installation. To verify the installation is successful, make sure the FortiClient version is 7.4.3 hotfix 1.8758 in the About page of the FortiClient GUI.
Nested VPN tunnels
FortiClient does not support parallel independent VPN connections to different sites. However, FortiClient may still establish VPN connection over existing third-party (for example, AT&T Client) VPN connection (nested tunnels).
SAML IdP configuration for Save Password
FortiClient provides an option to the end user to save their VPN login password with or without SAML configured. When using SAML, this feature relies on persistent sessions being configured in the identity provider (IdP), discussed as follows:
If the IdP does not support persistent sessions, FortiClient cannot save the SAML password. The end user must provide the password to the IdP for each VPN connection attempt.
The FortiClient save password feature is commonly used along with autoconnect and always-up features.
FortiClient support for newer Realtek drivers in Windows 11
Issues regarding FortiClient support for newer Realtek drivers in Windows 11 have been resolved. The issue is that Realtek and Qualcomm used the NetAdapterCx structure in their drivers, and Microsoft's API had an error in translating the flags, which may result in IPsec VPN connection failure.
FortiGuard Web Filtering category v10 update
Fortinet has updated its web filtering categories to v10, which includes two new URL categories for AI chat and cryptocurrency websites. To use the new categories, customers must upgrade their Fortinet products to one of the versions below:
- FortiManager - Fixed in 6.0.12, 6.2.9, 6.4.7, 7.0.2, 7.2.0, 7.4.0.
- FortiOS - Fixed in 7.2.8 and 7.4.1.
- FortiClient - Fixed in Windows 7.2.3, macOS 7.2.3, Linux 7.2.3.
- FortiClient EMS - Fixed in 7.2.1.
- FortiMail - Fixed in 7.0.7, 7.2.5, 7.4.1.
- FortiProxy - Fixed in 7.4.1.
See the following CSB for more information to caveats on the usage in FortiManager and FortiOS: https://support.fortinet.com/Information/Bulletin.aspx