Fortinet, Inc.

First CVE: Feb 1, 2017Active for: 9 years
1,029
CVEs Published
More CVEs Published than 91% of tracked CNAs
102.9
Avg CVEs / Year
More Avg CVEs / Year than 90% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked CNAs
2.7%
In CISA KEV
Higher KEV Rate than 93% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Fortinet, Inc. as a CNA, 98.8% affect products that Fortinet, Inc. develops as a vendor.

98.8%
Self-reported: 1,017Third-party: 12

Of all the CVEs published that affect products developed by Fortinet, Inc., 89.4% are self-published by Fortinet, Inc. as a CNA.

89.4%
10.6%
Self-published: 1,017Published by other CNAs: 120

Trends Over Time

The number and severity of CVEs published by Fortinet, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2017
9 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs

All CVEs published by Fortinet, Inc. as a CNA, regardless of affected vendor or product.

1,029 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe
Nov 14, 20259.899YESYES
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version
Oct 18, 20229.899YESYES
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0
Jun 4, 20199.899YESYES
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execut
Apr 14, 20269.898YESYES
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted re
Apr 4, 20269.898YESYES
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to exec
Feb 6, 20269.898YESYES
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.
Jul 17, 20259.898YESYES
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7
Jan 14, 20259.898YESYES
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiMa
Oct 23, 20249.898YESYES
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 a
Mar 12, 20249.898YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,029 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local204 (19.8%)
Network803 (78.0%)
Unknown0 (0.0%)
Physical3 (0.3%)
Adjacent Network19 (1.8%)
Attack Complexity
Low939 (91.3%)
High90 (8.7%)
Unknown0 (0.0%)
User Interaction
None850 (82.6%)
Unknown0 (0.0%)
Required179 (17.4%)
Privileges Required
Low435 (42.3%)
High192 (18.7%)
None402 (39.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1029 CVEs).

CISA KEV
28 CVEs
2.7% of CVEs· 93rd percentile
Metasploit
8 CVEs
0.8% of CVEs· 85th percentile
Nuclei
25 CVEs
2.4% of CVEs· 88th percentile
ExploitDB
12 CVEs
1.2% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Fortinet, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Fortinet, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs