VulnSea

Fortinet has 62 CVEs on record between 2019 and 2026. Disclosure cadence is accelerating: 20 in the last 90 days against 7 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 7.0 (medium), with 14 rated critical. 21% have been exploited in the wild — well above the 1% corpus average, so Fortinet flaws are worth patching on sight. The median gap from publication to a KEV listing is 130 days (12 cases). The dominant weakness classes are CWE-78 (5) and CWE-787 (5). Most affected products: fortiproxy (12), FortiOS (10), FortiAnalyzer (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
21% vs 1% corpus
Median CVSS
7.0
Publish → KEV
130 d median(12)
Last 90 days
20 prev 7

Products

  • fortiproxy 12
  • FortiOS 10
  • FortiAnalyzer 6
  • FortiSandbox 4
  • fortiweb 4
  • fortiwebmanager 4
62
Total CVEs
14
Critical
13
CISA KEV
13
Exploited
Fortinet vulnerabilities (CVEs) — page 3 · VulnSea