Skip to main content
SteveJW
New Member
June 25, 2026
Question

Vague "Patching Failed" alerts FortiClient

  • June 25, 2026
  • 5 replies
  • 88 views

The FortiEMS server is running version 7.4.7, while the client version on the workstations and servers is 7.4.5.
We plan to upgrade soon.
In the clients' "Notifications" tab, I see many "Patching Failed" alerts.


The installers were never created with the "Auto update to the Latest Patch" option enabled.
"Automatic Patching" is also disabled in the Vulnerability Scan settings.
We never perform upgrades or patching automatically; we prefer to manage that process ourselves.
So, what is triggering these "Patching Failed" alerts?
Thanks

5 replies

Stephen_G
Staff & Editor
Staff & Editor
June 29, 2026

Hi SteveJW,

 

Thanks for using Fortinet Community forums. We’ll look to get you an answer or help. 

 

Have a nice day,

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
July 1, 2026

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
July 2, 2026

Hi again SteveJW,

I talked with one of our engineers, and it doesn’t seem like this is something to be concerned about. Essentially, these ‘Patching failed’ messages are confirmations that auto-updating is not going through.

I’ll quote the person I spoke to:

Vulnerability scanning works by triggering the application to go home, retrieve an update, install, reboot if necessary.

If the application does not have this capability, auto-remediation fails, fc then displays the option to patch manually.

It is possible that 'Patching Failed' simply means that the app was unable to auto-update itself.

 

fc has no input on how the application updates, it can only trigger the application to auto-update. 

 

for windows os patching, the behaviour is different.

fc checks the vulnerability db for Microsoft's kbs and their level of vulnerability. if there are any at the level the ems admin wants the OS to be patched at, ie. critical, fc triggers a windows update to only retrieve the missing kb from the OS, then windows update takes over to install.  if a reboot is required by windows, fc relays this to the user.  on occasion the update fails to install causing fc rescan, request the update, fail the update, then repeat. 

fix for this repeat loop is for the admin to remove the offending kb.

 

Hope that helps!

Stephen_G - Fortinet Community Team
jie
Staff
Staff
July 2, 2026

Hi Steve,

Are they OS vulnerabilities or application vulnerabilities?

SteveJW
SteveJWAuthor
New Member
July 7, 2026

It is not the OS vulnerability scan, as that is disabled.
So, the assumption is that it is the application vulnerability scan.
 

Â