A critical software defect (Bug ID: 1286219) has been identified in Fortinet’s FortiSwitch operating system that causes the Network Time Protocol (NTP) daemon to freeze and consume excessive CPU resources on affected devices. The issue manifests after approximately 250 days of continuous uptime, potentially leading to severe degradation or loss of management or complete disruption of network infrastructure operations.
The NTP daemon — responsible for synchronizing the system clock with external time sources — enters an abnormal state after roughly 250 days (~8 months) of uninterrupted operation. Once triggered, the process monopolizes CPU cycles to the point where normal switch functions (e.g., packet forwarding, management plane access, spanning tree calculations) may become unresponsive or critically degraded.
Example scenario: A FortiSwitch FS-448E-FPOE deployed in a distribution layer has been running without interruption for 251 days. Suddenly, administrators notice massive network interrupts and loss of management access. FortiGate Switch Logs show repeated high CPU logs from time to time, which may be traced back to the ntpd process.
In problematic environments we could notice the following pattern, that when filtering for CPU related entries, all the affected switches were reporting high CPU alarms, which quickly have been cleared again. The high CPU could not be noticed on the switch itself, only based on the logged alarms:

This type of failure is particularly dangerous in enterprise environments where switches are expected to maintain years of continuous uptime without intervention and probably the full environment was maintained and upgraded on the same day.
Affected Versions
| FortiSwitch OS Version | Status |
|---|---|
| <7.6.6 | Possibly affected |
| 7.6.6 | Affected |
| 8.0.0 | Affected |
Please consult the Fortinet Compatibility Matrix prior upgrading the switches: https://docs.fortinet.com/document/fortiswitch/8.0.0/fortilink-compatibility
If you are running FortiOS 7.4.x (FortiGateOS) the only supported switch version is still FortiSwitch 7.6.6! Sadly there’s currently no final solution for customers with this FortiOS branch unless the workaround of the reboot of the switches.
Affected Models
The bug impacts a wide range of FortiSwitch hardware platforms, including access, distribution, and PoE-capable models:
- FSR-424F-POE
- FS-110G-FPOE
- FS-124F / FS-124F-FPOE / FS-124F-POE
- FS-124G / FS-124G-FPOE
- FS-148F / FS-148F-FPOE / FS-148F-POE
- FS-424E / FS-424E-Fiber / FS-424E-FPOE / FS-424E-POE
- FS-M426E-FPOE
- FS-448E / FS-448E-FPOE / FS-448E-POE
Workaround
If an immediate update is not possible, a restart of the affected switch will temporarily resolve the high CPU condition. However, note that:
- The issue will recur after another ~250 days of uptime.
- A restart causes a network outage for all connected devices on that switch.
- Scheduling proactive maintenance reboots before the 250-day mark can mitigate unplanned outages.
Permanent Solution
Fortinet has addressed this defect in the following patched releases:
| Fixed Version | Availability |
|---|---|
| FortiSwitch OS 7.6.7 | ✅ Available |
| FortiSwitch OS 8.0.1 | 🟡 Soon Available |
Recommendation: Upgrade all affected devices to the patched firmware as soon as possible during a planned maintenance window.
Sources
- Fortinet Release Notes — FortiSwitch 7.6.6: https://docs.fortinet.com/document/fortiswitch/7.6.6/fortiswitchos-release-notes/700712/known-issues
- Fortinet Release Notes — FortiSwitch 7.6.7: https://docs.fortinet.com/document/fortiswitch/7.6.7/fortiswitchos-release-notes/255778/resolved-issues
- Fortinet Release Notes — FortiSwitch 8.0.0: https://docs.fortinet.com/document/fortiswitch/8.0.0/fortiswitchos-release-notes/700712/known-issues
![]()
