Fortinet, Inc.
First CVE: Feb 1, 2017Active for: 9 years
1,029
CVEs Published
More CVEs Published than 91% of tracked CNAs
102.9
Avg CVEs / Year
More Avg CVEs / Year than 90% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked CNAs
2.7%
In CISA KEV
Higher KEV Rate than 93% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Fortinet, Inc. as a CNA, 98.8% affect products that Fortinet, Inc. develops as a vendor.
98.8%
Self-reported: 1,017Third-party: 12
Of all the CVEs published that affect products developed by Fortinet, Inc., 89.4% are self-published by Fortinet, Inc. as a CNA.
89.4%
10.6%
Self-published: 1,017Published by other CNAs: 120
Trends Over Time
The number and severity of CVEs published by Fortinet, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2017
9 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
Top CVEs
All CVEs published by Fortinet, Inc. as a CNA, regardless of affected vendor or product.
1,029 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64446CRITICAL A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe | Nov 14, 2025 | 9.8 | 99 | YES | YES |
CVE-2022-40684CRITICAL An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version | Oct 18, 2022 | 9.8 | 99 | YES | YES |
CVE-2018-13379CRITICAL An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 | Jun 4, 2019 | 9.8 | 99 | YES | YES |
CVE-2026-39808CRITICAL A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execut | Apr 14, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-35616CRITICAL A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted re | Apr 4, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-21643CRITICAL An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to exec | Feb 6, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-25257CRITICAL An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4. | Jul 17, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-55591CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7 | Jan 14, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-47575CRITICAL A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiMa | Oct 23, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-48788CRITICAL A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 a | Mar 12, 2024 | 9.8 | 98 | YES | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA1,029 CVEs
46%
39%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local204 (19.8%)
Network803 (78.0%)
Unknown0 (0.0%)
Physical3 (0.3%)
Adjacent Network19 (1.8%)
Attack Complexity
Low939 (91.3%)
High90 (8.7%)
Unknown0 (0.0%)
User Interaction
None850 (82.6%)
Unknown0 (0.0%)
Required179 (17.4%)
Privileges Required
Low435 (42.3%)
High192 (18.7%)
None402 (39.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (1029 CVEs).
CISA KEV
28 CVEs
2.7% of CVEs· 93rd percentile
Metasploit
8 CVEs
0.8% of CVEs· 85th percentile
Nuclei
25 CVEs
2.4% of CVEs· 88th percentile
ExploitDB
12 CVEs
1.2% of CVEs· 83rd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Fortinet, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Fortinet, Inc. as a CNA — matched by CVE ID, not by organization name.