Skip to main content
TechMSB
New Member
October 20, 2025
Question

ForticlientVPN only version 7.4.4?

  • October 20, 2025
  • 25 replies
  • 16918 views

Hello, I opened a case with support asking about a 7.4.4 version of Forticlientvpn only for windows , they suggested we post here.  

My questions are:

1) Is there a version of forticlient vpn only 7.4.4 coming out for windows?

2) If no can you verify if forticlient vpn only 7.4.3 for windows is not susceptible to https://fortiguard.fortinet.com/psirt/FG-IR-25-685

 

Thanks!

25 replies

AEK
SuperUser
SuperUser
October 21, 2025

Hi TechMSB

After searching on the support portal I can confirm the latest FortiClientVPN version is 7.4.3 so far.

The psirt page you shared mentions FCT and not FCT VPN, but it is obvious that the vulnerability can especially be exploited in shared environments where you share the installer in a folder that can be writable by anyone.

In any case there is a mentioned workaround that is simple to implement: just download the installer from Fortinet and put it in a read-only shared folder (basic security measures).

AEK
NAS
New Member
October 21, 2025

Hello everyone,
take a look at the release notes for FortiClient 7.4.4:

“FortiClient (Windows) 7.4.4 does not include a new version of the free VPN-only agent as no feature updates were made to the free VPN-only agent between 7.4.3 and 7.4.4. Users can continue to use the FortiClient (Windows) 7.4.3 free VPN-only agent.”

To me, it’s not entirely clear whether there will still be a VPN-only version in the future, or if there just isn’t one for 7.4.4 because there were no changes. The text in the release notes also appears to have been updated.

Now we’ll see whether the VPN-only version continues to exist. If not, that would be quite unfortunate in my opinion.

 

Best regards,
Karsten

Yurisk
SuperUser
SuperUser
October 22, 2025

I couldn't get the answer from any of my sources, seems like no one really knows/wants to share if there is change of plans for free VPN-only client. I will be watching closely this topic, if FOrtinet indeed to drop free vpn-only client without offering decentralized licensing model, it would be a major blow, as in MSP environment switching hundreds of unrelated clients with thousands of users to a centralized EMS is a no go.

TechMSB
TechMSBAuthor
New Member
November 19, 2025

I just saw there are more risks for 7.4.3 vpn only client but still not new version from fortinet.

https://fortiguard.fortinet.com/psirt/FG-IR-25-125

https://fortiguard.fortinet.com/psirt/FG-IR-25-112

 

We don't need the full vpn and edr version just the vpn only version.

 

 

RHHSupport
Explorer
November 19, 2025

Correct. The last CVE:  CVE-2025-46373 has a High severity and is also for the VPN only Client.

I have heard from support they are working on a VPN Only version of 7.4.4 but no ETA yet.

We have to wait and are stuck with vulnerable version 7.4.3 of the VPN only Client. 

TechMSB
TechMSBAuthor
New Member
November 19, 2025

Thanks for the update, hope it's soon!

FaltecITSupport
New Member
November 26, 2025

Reading into this, as we are also affected. Has anyone reviewed https://www.cvedetails.com/cve/CVE-2025-57716? This seems to suggest that 7.2.12 is unaffected by this, but this is no longer available for download and may have other vulnerabilities.

Nate_Allen_OCDC
Explorer
December 9, 2025

I was directed by my reseller to use the 7.2 version with the claim it's not affected.  I should not have to use an ancient version of the VPN software just because Fortinet doesn't want to take a few hours to patch the free client.  I will be remembering this situation when it's time for my company to find a different managed firewall provider.

TechMSB
TechMSBAuthor
New Member
November 28, 2025

I am told they are testing a fix to be included in an official build, no ETA yet though.

AEK
SuperUser
SuperUser
November 29, 2025

Keep in mind that FCT VPN is a free version with no obligation from Fortinet.

AEK
RHHSupport
Explorer
November 29, 2025

Even though if it is free, as a reputable security company you would expect them not to actively distribute a product with a high severity vulnerability. At least make your users aware and disable the download. 

alomah3
New Member
November 29, 2025

It does include fixes like: "Issues regarding FortiClient support for newer Realtek drivers in W indows 11 have been resolved. The issue is that Realtek and Qualcomm used the NetAdapterCx structure in their drivers and the Microsoft API had an error in translating the flags, which may result in IPsec VPN connection failure."

Nate_Allen_OCDC
Explorer
December 3, 2025

Does anyone have the current status of the 7.4.4 VPN-only client?  It has been quite a while since these vulnerabilities were released.  I wish I could use the supported version, but I am a tiny firm that has an outsourced firewall and all I have to use is the VPN-only client, so short of completely changing firewalls and vendors (which I also wish I could do but cannot) I am stuck.

TechMSB
TechMSBAuthor
New Member
December 3, 2025

I was told development was working on a patch for 7.4.3 vpn client only but so far all I seen is the full client, not the vpn only.  I understand this is free software but I agree with others that security risks should be patched.