Sora Yazılım
Network security, server and software solutions from Türkiye

Firewall Vulnerability and Patch Management: A FortiGate Guide

In short: Internet-facing firewalls and VPN gateways are prime targets because their management and VPN components can be reached before anyone logs in. Effective firewall patch management looks beyond the CVSS score: check the vendor advisory and the CISA KEV entry, weigh exposure and business impact, and restrict management access while the patch is scheduled.

Why is a firewall vulnerability such an attractive target?

Because a firewall or VPN gateway is reachable from anywhere on the internet and is itself the door to the internal network. The Canadian Centre for Cyber Security (CCCS) guidance ITSM.80.101 (February 2025) notes that edge devices usually have public IP addresses, which makes them particularly susceptible to exploitation. It adds that targeting edge devices has become a tactic of choice for many threat actors, including state-sponsored ones.

Verizon's 2025 Data Breach Investigations Report (DBIR) found that edge devices and VPNs were the target in 22% of vulnerability exploitation actions, up from 3% in the previous report. Of 17 sampled edge device vulnerabilities, 9 entered the KEV catalogue on or before their CVE publication day, leaving defenders no head start. The 2026 DBIR executive summary reports that exploitation is now the most common initial access vector (31%), and it also ranks first for small and medium-sized businesses (26%).

A compromised firewall affects far more than one server: the same device often carries VPN, web filtering, application control and policies that govern generative AI use. Edge device patches therefore deserve their own, faster maintenance group.

What does the CISA KEV catalogue show about FortiGate and FortiOS?

The Known Exploited Vulnerabilities (KEV) catalogue of CISA (the US Cybersecurity and Infrastructure Security Agency) lists vulnerabilities with confirmed exploitation in the wild. The version 2026.10.04 we downloaded on 7 October 2026 contains 1,734 entries. NIST SP 800-40 Rev. 4 notes that US federal agencies must remediate these entries by set deadlines, while other organisations may use the catalogue voluntarily for prioritisation.

We counted the JSON data ourselves. Between 1 January 2025 and 4 October 2026, 495 entries were added; 16 concern Fortinet products (8 in 2025, 8 in 2026), and 7 of those involve FortiOS (the FortiGate operating system). Classifying firewall, VPN/remote access gateway and application delivery (ADC) products by name, we found 48 of the 495 entries (roughly one in ten) in that group; 14 of them are flagged "Known" for ransomware use.

Two observations matter for patching. Old flaws keep appearing: 6 of the 48 carry CVE IDs from 2015–2023, so unpatched legacy devices stay targets. And deadlines have shortened: for 226 of the 245 entries added in 2025, the gap between the date added and the due date was 21 days; for 125 of the 250 entries added in 2026, it was 3 days.

CVE (added to KEV)Fixed FortiOS versions (or later)Interim measure in the advisory
CVE-2024-55591 (14 Jan 2025)7.0.17 (7.2, 7.4 and 7.6 not affected)Disable the HTTP/HTTPS admin interface or limit it to allowed addresses with a local-in policy
CVE-2019-6693 (25 Jun 2025)5.6.11, 6.0.7, 6.2.1 plus the private-data-encryption settingPassword-protect configuration backups; never share configuration in public channels
CVE-2025-59718 / CVE-2025-59719 (16 Dec 2025)7.6.4, 7.4.9, 7.2.12, 7.0.18Turn off administrative login via FortiCloud SSO
CVE-2026-24858 (27 Jan 2026)7.6.6, 7.4.11, 7.2.13, 7.0.19Review all administrator accounts for unexpected entries
CVE-2025-68686 (27 Jul 2026)7.6.2, 7.4.7; migrate to a fixed branch for 7.2, 7.0 and 6.4Devices that never had SSL-VPN enabled are not affected; an FMWP virtual patch was published
CVE-2025-25249 (9 Sep 2026)7.6.4, 7.4.9, 7.2.12, 7.0.18; migrate to a fixed branch for 6.4Remove "fabric" access from interfaces or restrict CAPWAP control ports with a local-in policy

Versions and measures come from the linked Fortinet PSIRT (Product Security Incident Response Team) advisories, accessed on 7 October 2026; advisories change, so open the current version before acting. Note that Fortinet rated CVE-2019-6693 (CVSS 4.2) and CVE-2025-68686 (CVSS 5.3) as "medium", yet both entered KEV. The advisory for CVE-2025-25249 (CVSS 7.4) still showed "Known Exploited: No" on our access date, although CISA had added it on 9 September 2026.

How do you track vendor advisories and the KEV catalogue?

Tracking starts with an inventory of the FortiOS version and enabled features on each device; an advisory is only useful once matched against it. Under Fortinet's vulnerability policy, PSIRT advisories are published on the second Tuesday of each month. Critical issues and active exploitation can trigger an out-of-cycle advisory, which may not yet include a complete set of patches or workarounds.

SourceWhat it gives youHow to follow it
Fortinet PSIRT (FortiGuard)Affected and fixed versions, workaround, CVSS and the "Known Exploited" fieldfortiguard.fortinet.com/psirt, the RSS feed and e-mail registration via the support portal
CISA KEV catalogueConfirmed exploitation, date added, due date, ransomware use and a forensic triage flagJSON/CSV files in the cisagov/kev-data GitHub repository, synchronised shortly after each catalogue update
National CERTSecurity notifications for your country; in Türkiye, USOM states they are now published via siberguvenlik.gov.trSubscribe to the national CERT channel

A weekly checklist:

  • Match new Fortinet advisories and newly added KEV entries for edge products against your inventory; if a "planned" item enters KEV, raise its priority.
  • Note whether the advisory's interim measure applies to your configuration (is FortiCloud SSO enabled, has SSL-VPN ever been used?).
  • Flag unsupported branches: Fortinet's policy covers only products that have not reached end of life, and medium-severity flaws are fixed only in the current and prior version.
  • Record each decision; NIST SP 800-40 Rev. 4 notes that per-asset patch history helps incident responders.

Which flaw should firewall patch management fix first?

Fix first the flaw that is known to be exploited and affects a component your device exposes to the internet; the CVSS score is only one input. NIST SP 800-40 Rev. 4 recommends being ready for four scenarios: routine patching, emergency patching, emergency mitigation and unpatchable assets. The matrix below is our own decision aid for choosing the scenario with three questions.

  • Exposure: is the affected component (management interface, SSL-VPN, IPsec, FortiCloud SSO, Fabric access) reachable from the internet, only internally, or disabled?
  • Exploitation status: is it in KEV or reported as exploited by the vendor, or only published?
  • Business impact: is the device the only internet exit, do branches and remote staff depend on it, is there an HA (high availability) pair?
Exploitation / ExposureInternet-facing componentInternal network onlyFeature disabled or unused
In KEV or vendor reports exploitationP1 Emergency: interim measure now, emergency window, then a compromise checkP2 Expedited: next short window, restrict access until thenP3 Planned: routine window, confirm the feature stays off
Published, no exploitation reportedP2 ExpeditedP3 PlannedP4 Routine cycle

Business impact does not change the class; it decides the method and the order. On a head-office device with an HA pair, the patch can follow a rolling upgrade; a branch with a single unit needs a short outage window and console access. Within a class, start with the device exposing the most services and users.

You set the time targets in your policy or service contract. For reference, NIST says emergency patching may take hours or days, and for half of the 2026 KEV additions (125 of 250) the US federal due date was 3 days. If a "P3" item enters KEV, reassess it the same day.

How do you schedule a FortiOS update into a maintenance window?

A FortiOS update follows a repeatable procedure: choose the target, prepare, roll out in stages, verify. Upgrade paths and rollback are covered in our FortiOS upgrade guide; here we summarise the steps that matter for patch management, alongside the FortiOS 7.6.5 Administration Guide.

  1. Choose the target version. Find the fixed version for your branch. "Migrate to a fixed release" (as for 6.4 in CVE-2025-25249) means a branch change, not a patch, and needs longer preparation.
  2. Check maturity and licence. Since FortiOS 7.2.0, releases carry a "Mature" or "Feature" tag. Moving to another minor release (such as 7.4 to 7.6) requires a valid FMWR (Firmware & General Updates) licence; keep FortiGate licence renewal on the patch calendar.
  3. Confirm the upgrade path. Fortinet advisories recommend reaching the fixed version through the intermediate builds suggested by the Upgrade Path Tool.
  4. Prepare. Back up the configuration and local certificates with a password, keep the current image, and have console access and rollback steps ready.
  5. Roll out in stages. As NIST suggests, start with a test unit or small branch ("canary"); for HA clusters, consider the vendor's uninterrupted cluster upgrade.
  6. Verify. Check the version, VPN tunnels, critical policies and logs; new firmware replaces antivirus and attack definitions, so confirm they are current.
  7. Check for compromise. For exploited flaws, review the advisory's indicators; FG-IR-26-060 recommends checking all administrator accounts for unexpected entries.
  8. Record and measure. Following NIST, track the share of patches applied by the deadline and the mean and median patch time.

According to the FortiOS 7.6.5 documentation, automatic patch upgrades are enabled by default on all FortiGate models. The device installs a new patch within the same minor release only, by default after a 3-day delay and at a random time between 02:00 and 04:00. It cannot be enabled on units in a Security Fabric, managed by FortiManager or acting as HA secondary. In a small single-device office it can reduce delays; larger estates are better served by a central plan with change records.

What compensating controls apply while you wait for a window?

Use compensating controls that shrink the attack surface; they protect the gap but do not replace the patch. NIST SP 800-40 Rev. 4 recommends scheduling both the permanent fix and the removal of each emergency mitigation. CCCS recommendations and Fortinet advisories largely overlap:

ControlWhat it achievesWatch out for
Keep the management interface off the internet; if needed, allow only the management network via local-in policy or trusted hostsBlocks access for flaws that target the management interfacePer FG-IR-24-535, trusted hosts match this only if set for every administrator; local-in policies are preferred
Disable unused features (FortiCloud SSO admin login, "fabric" access on WAN interfaces, unused SSL-VPN)Turns off the affected componentPer FG-IR-25-647, registering a device to FortiCare from the GUI enables FortiCloud SSO unless the toggle is switched off
Phishing-resistant multi-factor authentication (MFA) and centralised authentication for admin accessA stolen password is no longer enoughMinimise local accounts; password-protect configuration backups
Off-device centralised logging with alerts on successful admin logins and configuration changesMakes a possible breach visible earlyKeep log detail as high as practical
Virtual patching on the management interface (FMWP database, virtual-patch in a local-in policy)Blocks known flaws with the IPS engineNeeds a valid FMWR licence; not for agentless VPN or ZTNA with client certificates

If you do not use SSL-VPN, disabling it removes the affected component in many advisories; FG-IR-25-934 states that devices which never had SSL-VPN enabled are not affected. For the FortiOS 7.6 changes and alternatives, see our SSL VPN migration plan and ZTNA guide. Keeping logs on a separate platform such as FortiAnalyzer helps you trust the records when the device itself is in doubt; for organisations in Türkiye, retention under Law 5651 is covered in our central log management article.

If you would like to map your devices' versions and exposure, or review interim measures for a pending advisory together, send us your request. Get a Quote

What does a maintenance or managed service model add to patching?

A maintenance or managed service model ties the gap between reading an advisory and applying the patch to defined responsibilities and a calendar. NIST SP 800-40 Rev. 4 lists sharing risk with a provider that takes care of patching as a "transfer" risk response; in every model, however, approving the maintenance window and judging business impact stay with the organisation.

TaskIn-house team onlyWith a maintenance or managed service
Following advisories and KEV, matching them to inventoryDepends on the time the team can spareA defined, recurring task in the contract
Prioritisation (exposure, exploitation, business impact)Done in-houseProvider proposes, organisation approves
Maintenance window and outage approvalOrganisationOrganisation
Upgrade, rollback and verificationDone in-houseScope defined in the contract

We compare service models in our article on managed firewall services, cover routine tasks in firewall maintenance and hardware faults in FortiGate maintenance and repair. Sora Yazılım offers maintenance and management support, including firmware planning, through its firewall maintenance and management service, and handles selection, supply and installation of FortiGate products. The scope is defined in each contract.

FAQ

Should I leave automatic patch upgrades enabled on FortiGate?

In small single-device sites that tolerate a short outage, leaving it on can reduce patch delays. According to FortiOS 7.6.5 documentation, the feature is on by default and installs patches only within the same minor release. It is unavailable on units managed by FortiManager, in a Security Fabric or acting as HA secondary, so those estates need a central, recorded patch plan.

Is a vulnerability that is not in KEV unimportant?

No. KEV lists vulnerabilities with confirmed exploitation; absence from the list proves nothing. Advisory FG-IR-25-084 still showed "Known Exploited: No" on our access date, yet the flaw was added to KEV on 9 September 2026. Treating high or critical flaws in internet-facing components as expedited, without waiting for KEV, is the more cautious approach.

Can I still get security patches if my licence expires?

Partly. According to FortiOS 7.6.5 documentation, a FortiGate without a valid FMWR licence, or at end of support, is upgraded automatically to the latest patch of its current minor release. Moving to the next minor or major release requires a valid licence, so an advisory that says "migrate to a fixed release" can be blocked by licence status. Track renewal dates with the patch calendar.

Is the device safe once the patch is applied?

The patch only closes the vulnerability. Fortinet's PSIRT analysis of April 2025 describes attackers who kept read-only access after patching, and recommends reviewing configuration. After an exploited flaw, review administrator accounts, local users, policy changes and logs, and start incident response if anything looks suspicious.

What happens if I stay on an old FortiOS branch such as 6.4?

For some flaws no patch is released for the old branch at all: the advisories for CVE-2025-25249 and CVE-2025-68686 list "migrate to a fixed release" for FortiOS 6.4. Fortinet's policy covers only products before end of life and fixes medium-severity flaws only in the current and prior version. Plan a branch migration or a hardware refresh for such devices.

Can this process be run with outside support?

Yes. Advisory tracking, inventory matching, prioritisation proposals, upgrades and verification can be shared with a service provider, while window approval and business impact decisions stay with you. The scope is defined in the contract. To discuss the version and exposure status of your current devices, contact us.

Conclusion

  • Edge devices are reachable from the internet, so they are targeted; in the 2025 DBIR, the edge and VPN share of exploitation rose from 3% to 22%.
  • Follow Fortinet advisories and the CISA KEV catalogue together; KEV 2026.10.04 lists 16 Fortinet entries added since the start of 2025.
  • Let exposure, exploitation and business impact set the priority; plan each patch with licence, upgrade path, backup, canary and verification steps.
  • While waiting, restrict management access, disable unused features, and use MFA and off-device logging.

Sora Yazılım supports FortiGate maintenance and management; the patch calendar is agreed in the contract.

Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · E-mail: talep@sorayazilim.com

Sources

  1. Known Exploited Vulnerabilities Catalog, catalogue version 2026.10.04 (JSON) — CISA, 2026. raw.githubusercontent.com (accessed 7 October 2026)
  2. PSIRT advisories FG-IR-24-535, FG-IR-19-007, FG-IR-25-647, FG-IR-26-060, FG-IR-25-934, FG-IR-25-084 — Fortinet, 2020–2026. fortiguard.fortinet.com (accessed 7 October 2026)
  3. Fortinet Security Vulnerability Policy — Fortinet PSIRT. fortiguard.fortinet.com (accessed 7 October 2026)
  4. Analysis of Threat Actor Activity — Fortinet PSIRT Blog, 10 April 2025. fortinet.com (accessed 7 October 2026)
  5. FortiOS 7.6.5 Administration Guide (automatic firmware upgrades, firmware licence, local-in virtual patching) — Fortinet. docs.fortinet.com, docs.fortinet.com, docs.fortinet.com (accessed 7 October 2026)
  6. Upgrade Path Tool — Fortinet Document Library. docs.fortinet.com (accessed 7 October 2026)
  7. NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning — NIST, April 2022. csrc.nist.gov
  8. Security considerations for edge devices (ITSM.80.101) — Canadian Centre for Cyber Security, February 2025. cyber.gc.ca
  9. 2025 Data Breach Investigations Report — Verizon, 2025. verizon.com (accessed 7 October 2026)
  10. 2026 DBIR Executive Summary — Verizon, 2026. verizon.com (accessed 7 October 2026)
  11. USOM notice on security notifications moving to siberguvenlik.gov.tr — USOM (Türkiye). usom.gov.tr

How this article was prepared

Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical details were checked against the vendor and official sources linked in the text as of 7 October 2026. KEV counts are our own, based on the catalogue's JSON data; the edge device classification relies on product names.

Related articles

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support