CVE Tools

Fortinet

1,069 CVEs tracked since 2005. Since Sep 2020, 16 of them reached CISA KEV.

Fortinet CVEs per month

Sep 2020 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Fortinet CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0950
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-0150
2021-0220
2021-03null or fewer
2021-0430
2021-05null or fewer
2021-0660
2021-07160
2021-08180
2021-0970
2021-1060
2021-11200
2021-12390
2022-01null or fewer
2022-0280
2022-03110
2022-04160
2022-0590
2022-06null or fewer
2022-07150
2022-0830
2022-09100
2022-1091
2022-11170
2022-1260
2023-0161
2023-02380
2023-03null or fewer
2023-04200
2023-0590
2023-06211
2023-0770
2023-08null or fewer
2023-09140
2023-10360
2023-11170
2023-12130
2024-0150
2024-02122
2024-0391
2024-04120
2024-05120
2024-06160
2024-07110
2024-0850
2024-09100
2024-10null or fewer
2024-11170
2024-12100
2025-01521
2025-02151
2025-03440
2025-04120
2025-05101
2025-06130
2025-0771
2025-08140
2025-09null or fewer
2025-10320
2025-11182
2025-12181
2026-0171
2026-02101
2026-03220
2026-04281
2026-05110
2026-06null or fewer
2026-07120
2026-08null or fewer
2026-09100

Products

The products that kept showing up in Fortinet's monthly top three, with their CVEs summed over those months.

  1. Fortios16935 months
  2. Fortiweb7111 months
  3. Fortiproxy6917 months
  4. Fortimanager5613 months
  5. Fortianalyzer359 months
  6. Fortisandbox287 months
  7. Fortiadc209 months
  8. Forticlient207 months
  9. Fortinet Fortiweb183 months
  10. Fortipam186 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Fortinet.

  1. CVE-2026-84388A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to informa...9.6
  2. CVE-2026-84390A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access ...9.8
  3. CVE-2026-84392A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions...2.7
  4. CVE-2026-84391A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>6.5
  5. CVE-2026-22575An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, Fort...4.9
  6. CVE-2026-84393A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <inser...8.1
  7. CVE-2026-26084A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5...9.9
  8. CVE-2026-84385A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSO...5.4
  9. CVE-2026-84389A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or comma...3.1
  10. CVE-2026-84386A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector ...5.1
  11. CVE-2026-84387A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4....7.2
  12. CVE-2026-70468A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1...8.1
  13. CVE-2026-26035An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12...9.8
  14. CVE-2026-70467A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions,...3.8
  15. CVE-2026-70466A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all v...5.3

The record

Peak rank
#12 in Mar 2012
Busiest month shown
Jan 2025, 52 CVEs
Months with a KEV entry
14 since Sep 2020
Monthly snapshots
117 since 2005
Fortinet's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store