Fortinet white logo
Fortinet white logo

Special notices

Special notices

FortiClient (Windows) 7.4.3 free VPN-only agent online installer update

The FortiClient (Windows) 7.4.3 free VPN-only agent online installer was updated on April 15, 2026 to address the following vulnerability:

Bug ID

Description

1188355

CVE-2025-57716

This issue does not affect users who have the FortiClient (Windows) 7.4.3 free VPN-only agent installed and running. It only affects those who have downloaded the FortiClient (Windows) 7.4.3 free VPN-only agent online installer before but have not installed it yet or have uninstalled it after initial installation. If you are affected, you must download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com before installing it. To verify the downloaded installer is the correct version, right-click the installer, select Properties, and make sure the version is 7.4.3.4799 in the Details tab.

FortiClient (Windows) 7.4.3 free VPN-only agent re-release

The FortiClient (Windows) 7.4.3 free VPN-only agent was re-released on March 20, 2026 to address the following vulnerabilities and issues:

Bug ID

Description

1129740

CVE-2025-46373

1147064

CVE-2025-47761

1188354

CVE-2025-66535

1193312

CVE-2025-62676

959868 CVE-2025-54660
1147064 CVE-2025-47761

1250474

CVE-2025-15467

1255625

FortiClient (Windows) fails to recognize the newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers.

1257484

FortiClient (Windows) inadvertently may poll FortiGuard for the Internet Service database (ISDB) every six hours.

To install the new version, download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com and double-click it to complete the installation. To verify the installation is successful, make sure the FortiClient version is 7.4.3.4726 in the About page of the FortiClient GUI.

FortiClient (Windows) 7.4.3 GA hotfix 1

FortiClient (Windows) 7.4.3 GA hotfix 1 (7.4.3.1790.1.8758) was released on December 11, 2025 to address the following vulnerabilities:

Bug ID

Description

1129740

CVE-2025-46373

1147064

CVE-2025-47761

1188354

CVE-2025-66535

To install the hotfix from EMS, collect the EMS serial numbers and contact Fortinet Support.

To install the hotfix locally:
  1. Download the FortiClientTools_7.4.3.8758.zip file from the Fortinet Support website.

  2. Unzip the file and copy the FortiClientTools_7.4.3.8758\SupportUtils\hotfix.exe file to the Downloads folder.

  3. Shutdown FortiClient and run the following installation command in PowerShell:

    C:\Users\ftntt\Downloads>cmd /k hotfix.exe
  4. When the Hotfix 7.4.3.8758 is now installed message is displayed, verify the following:

    • The C:\windows\system32\driver\fortips_74.sys file has been updated (check modification date)

    • The C:\Program Files\Fortinet\FortiClient\resources\app.asar file has been updated (check modification date)

    • The FortiClient version is 7.4.3 hotfix 1.8758 in the About page of the FortiClient GUI.

FortiClient (Windows) 7.4.3 free VPN-only agent GA update 1

FortiClient (Windows) 7.4.3 free VPN-only agent GA update 1 (7.4.3.1790.1.8758) was released on December 11, 2025 to address the following vulnerabilities:

Bug ID

Description

1129740

CVE-2025-46373

1147064

CVE-2025-47761

1188354

CVE-2025-66535

To install the update, download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com and double-click it to complete the installation. To verify the installation is successful, make sure the FortiClient version is 7.4.3 hotfix 1.8758 in the About page of the FortiClient GUI.

Nested VPN tunnels

FortiClient does not support parallel independent VPN connections to different sites. However, FortiClient may still establish VPN connection over existing third-party (for example, AT&T Client) VPN connection (nested tunnels).

SAML IdP configuration for Save Password

FortiClient provides an option to the end user to save their VPN login password with or without SAML configured. When using SAML, this feature relies on persistent sessions being configured in the identity provider (IdP), discussed as follows:

If the IdP does not support persistent sessions, FortiClient cannot save the SAML password. The end user must provide the password to the IdP for each VPN connection attempt.

The FortiClient save password feature is commonly used along with autoconnect and always-up features.

FortiClient support for newer Realtek drivers in Windows 11

Issues regarding FortiClient support for newer Realtek drivers in Windows 11 have been resolved. The issue is that Realtek and Qualcomm used the NetAdapterCx structure in their drivers, and Microsoft's API had an error in translating the flags, which may result in IPsec VPN connection failure.

FortiGuard Web Filtering category v10 update

Fortinet has updated its web filtering categories to v10, which includes two new URL categories for AI chat and cryptocurrency websites. To use the new categories, customers must upgrade their Fortinet products to one of the versions below:

  • FortiManager - Fixed in 6.0.12, 6.2.9, 6.4.7, 7.0.2, 7.2.0, 7.4.0.
  • FortiOS - Fixed in 7.2.8 and 7.4.1.
  • FortiClient - Fixed in Windows 7.2.3, macOS 7.2.3, Linux 7.2.3.
  • FortiClient EMS - Fixed in 7.2.1.
  • FortiMail - Fixed in 7.0.7, 7.2.5, 7.4.1.
  • FortiProxy - Fixed in 7.4.1.

See the following CSB for more information to caveats on the usage in FortiManager and FortiOS: https://support.fortinet.com/Information/Bulletin.aspx

Special notices

Special notices

FortiClient (Windows) 7.4.3 free VPN-only agent online installer update

The FortiClient (Windows) 7.4.3 free VPN-only agent online installer was updated on April 15, 2026 to address the following vulnerability:

Bug ID

Description

1188355

CVE-2025-57716

This issue does not affect users who have the FortiClient (Windows) 7.4.3 free VPN-only agent installed and running. It only affects those who have downloaded the FortiClient (Windows) 7.4.3 free VPN-only agent online installer before but have not installed it yet or have uninstalled it after initial installation. If you are affected, you must download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com before installing it. To verify the downloaded installer is the correct version, right-click the installer, select Properties, and make sure the version is 7.4.3.4799 in the Details tab.

FortiClient (Windows) 7.4.3 free VPN-only agent re-release

The FortiClient (Windows) 7.4.3 free VPN-only agent was re-released on March 20, 2026 to address the following vulnerabilities and issues:

Bug ID

Description

1129740

CVE-2025-46373

1147064

CVE-2025-47761

1188354

CVE-2025-66535

1193312

CVE-2025-62676

959868 CVE-2025-54660
1147064 CVE-2025-47761

1250474

CVE-2025-15467

1255625

FortiClient (Windows) fails to recognize the newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers.

1257484

FortiClient (Windows) inadvertently may poll FortiGuard for the Internet Service database (ISDB) every six hours.

To install the new version, download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com and double-click it to complete the installation. To verify the installation is successful, make sure the FortiClient version is 7.4.3.4726 in the About page of the FortiClient GUI.

FortiClient (Windows) 7.4.3 GA hotfix 1

FortiClient (Windows) 7.4.3 GA hotfix 1 (7.4.3.1790.1.8758) was released on December 11, 2025 to address the following vulnerabilities:

Bug ID

Description

1129740

CVE-2025-46373

1147064

CVE-2025-47761

1188354

CVE-2025-66535

To install the hotfix from EMS, collect the EMS serial numbers and contact Fortinet Support.

To install the hotfix locally:
  1. Download the FortiClientTools_7.4.3.8758.zip file from the Fortinet Support website.

  2. Unzip the file and copy the FortiClientTools_7.4.3.8758\SupportUtils\hotfix.exe file to the Downloads folder.

  3. Shutdown FortiClient and run the following installation command in PowerShell:

    C:\Users\ftntt\Downloads>cmd /k hotfix.exe
  4. When the Hotfix 7.4.3.8758 is now installed message is displayed, verify the following:

    • The C:\windows\system32\driver\fortips_74.sys file has been updated (check modification date)

    • The C:\Program Files\Fortinet\FortiClient\resources\app.asar file has been updated (check modification date)

    • The FortiClient version is 7.4.3 hotfix 1.8758 in the About page of the FortiClient GUI.

FortiClient (Windows) 7.4.3 free VPN-only agent GA update 1

FortiClient (Windows) 7.4.3 free VPN-only agent GA update 1 (7.4.3.1790.1.8758) was released on December 11, 2025 to address the following vulnerabilities:

Bug ID

Description

1129740

CVE-2025-46373

1147064

CVE-2025-47761

1188354

CVE-2025-66535

To install the update, download the latest FortiClient VPN-only agent installation file for Windows from FortiClient.com and double-click it to complete the installation. To verify the installation is successful, make sure the FortiClient version is 7.4.3 hotfix 1.8758 in the About page of the FortiClient GUI.

Nested VPN tunnels

FortiClient does not support parallel independent VPN connections to different sites. However, FortiClient may still establish VPN connection over existing third-party (for example, AT&T Client) VPN connection (nested tunnels).

SAML IdP configuration for Save Password

FortiClient provides an option to the end user to save their VPN login password with or without SAML configured. When using SAML, this feature relies on persistent sessions being configured in the identity provider (IdP), discussed as follows:

If the IdP does not support persistent sessions, FortiClient cannot save the SAML password. The end user must provide the password to the IdP for each VPN connection attempt.

The FortiClient save password feature is commonly used along with autoconnect and always-up features.

FortiClient support for newer Realtek drivers in Windows 11

Issues regarding FortiClient support for newer Realtek drivers in Windows 11 have been resolved. The issue is that Realtek and Qualcomm used the NetAdapterCx structure in their drivers, and Microsoft's API had an error in translating the flags, which may result in IPsec VPN connection failure.

FortiGuard Web Filtering category v10 update

Fortinet has updated its web filtering categories to v10, which includes two new URL categories for AI chat and cryptocurrency websites. To use the new categories, customers must upgrade their Fortinet products to one of the versions below:

  • FortiManager - Fixed in 6.0.12, 6.2.9, 6.4.7, 7.0.2, 7.2.0, 7.4.0.
  • FortiOS - Fixed in 7.2.8 and 7.4.1.
  • FortiClient - Fixed in Windows 7.2.3, macOS 7.2.3, Linux 7.2.3.
  • FortiClient EMS - Fixed in 7.2.1.
  • FortiMail - Fixed in 7.0.7, 7.2.5, 7.4.1.
  • FortiProxy - Fixed in 7.4.1.

See the following CSB for more information to caveats on the usage in FortiManager and FortiOS: https://support.fortinet.com/Information/Bulletin.aspx