Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fortinet, Inc.

First CVE: Jun 1, 2005Active for: 21 yearsTotal CVEs: 1,137
60.7
VTI Score
TOP TARGET

Fortinet, Inc. maintains a broadly represented portfolio of network security and infrastructure appliances, including firewalls, web application firewalls, proxies, and centralized management and analytics platforms, deployed widely across enterprise perimeter defense and threat monitoring operations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and they recur across flagship products such as FortiOS, FortiWeb, FortiProxy, FortiManager, and FortiAnalyzer. The exposure concentrates in weakness classes characteristic of security appliances that parse and process untrusted network traffic: cross-site scripting, OS command injection, path traversal, and sensitive information disclosure, alongside categories that reflect the scope and complexity of platform logic. Because these products are positioned at security boundaries and are often internet-facing or trusted to make access decisions, vulnerabilities here carry outsized operational risk and warrant prioritized monitoring and patching. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
1,137
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
2.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Fortinet, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2005
21 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Self-Reporting Analysis

Of all the CVEs published by Fortinet, Inc. as a CNA, 98.8% affect products that Fortinet, Inc. develops as a vendor.

98.8%
Self-reported: 1,017 (98.8%)
Third-party: 12 (1.2%)

Of all the CVEs published that affect products developed by Fortinet, Inc., 89.4% are self-published by Fortinet, Inc. as a CNA.

89.4%
10.6%
Self-published: 1,017 (89.4%)
Other CNAs: 120 (10.6%)

Products(246 total)

Top CVEs

Signals from CVEs in this vendor scope (1137 CVEs).

1,137 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-64446CRITICAL
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe
Nov 14, 20259.899YESYES
CVE-2022-40684CRITICAL
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version
Oct 18, 20229.899YESYES
CVE-2018-13379CRITICAL
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0
Jun 4, 20199.899YESYES
CVE-2026-39808CRITICAL
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execut
Apr 14, 20269.898YESYES
CVE-2026-35616CRITICAL
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted re
Apr 4, 20269.898YESYES
CVE-2026-21643CRITICAL
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to exec
Feb 6, 20269.898YESYES
CVE-2025-25257CRITICAL
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.
Jul 17, 20259.898YESYES
CVE-2024-55591CRITICAL
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7
Jan 14, 20259.898YESYES
CVE-2024-47575CRITICAL
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiMa
Oct 23, 20249.898YESYES
CVE-2023-48788CRITICAL
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 a
Mar 12, 20249.898YESYES
View all 1,137 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,137 CVEs
48%
38%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local206 (18.1%)
Network828 (72.8%)
Unknown80 (7.0%)
Physical3 (0.3%)
Adjacent Network20 (1.8%)
Attack Complexity
Low965 (84.9%)
High92 (8.1%)
Unknown80 (7.0%)
User Interaction
None863 (75.9%)
Unknown80 (7.0%)
Required194 (17.1%)
Privileges Required
Low449 (39.5%)
High194 (17.1%)
None414 (36.4%)
Unknown80 (7.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (1137 CVEs).

CISA KEV
28 CVEs
2.5% of CVEs· 99th percentile
Metasploit
9 CVEs
0.8% of CVEs· 97th percentile
Nuclei
27 CVEs
2.4% of CVEs· 95th percentile
ExploitDB
24 CVEs
2.1% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fortinet, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fortinet, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fortinet, Inc.'s Products

View all 4 CNAs →

Top CWEs