Fortinet
1,069 CVEs tracked since 2005. Since Sep 2020, 16 of them reached CISA KEV.
Fortinet CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-09 | 5 | 0 |
| 2020-10 | null or fewer | |
| 2020-11 | null or fewer | |
| 2020-12 | null or fewer | |
| 2021-01 | 5 | 0 |
| 2021-02 | 2 | 0 |
| 2021-03 | null or fewer | |
| 2021-04 | 3 | 0 |
| 2021-05 | null or fewer | |
| 2021-06 | 6 | 0 |
| 2021-07 | 16 | 0 |
| 2021-08 | 18 | 0 |
| 2021-09 | 7 | 0 |
| 2021-10 | 6 | 0 |
| 2021-11 | 20 | 0 |
| 2021-12 | 39 | 0 |
| 2022-01 | null or fewer | |
| 2022-02 | 8 | 0 |
| 2022-03 | 11 | 0 |
| 2022-04 | 16 | 0 |
| 2022-05 | 9 | 0 |
| 2022-06 | null or fewer | |
| 2022-07 | 15 | 0 |
| 2022-08 | 3 | 0 |
| 2022-09 | 10 | 0 |
| 2022-10 | 9 | 1 |
| 2022-11 | 17 | 0 |
| 2022-12 | 6 | 0 |
| 2023-01 | 6 | 1 |
| 2023-02 | 38 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 20 | 0 |
| 2023-05 | 9 | 0 |
| 2023-06 | 21 | 1 |
| 2023-07 | 7 | 0 |
| 2023-08 | null or fewer | |
| 2023-09 | 14 | 0 |
| 2023-10 | 36 | 0 |
| 2023-11 | 17 | 0 |
| 2023-12 | 13 | 0 |
| 2024-01 | 5 | 0 |
| 2024-02 | 12 | 2 |
| 2024-03 | 9 | 1 |
| 2024-04 | 12 | 0 |
| 2024-05 | 12 | 0 |
| 2024-06 | 16 | 0 |
| 2024-07 | 11 | 0 |
| 2024-08 | 5 | 0 |
| 2024-09 | 10 | 0 |
| 2024-10 | null or fewer | |
| 2024-11 | 17 | 0 |
| 2024-12 | 10 | 0 |
| 2025-01 | 52 | 1 |
| 2025-02 | 15 | 1 |
| 2025-03 | 44 | 0 |
| 2025-04 | 12 | 0 |
| 2025-05 | 10 | 1 |
| 2025-06 | 13 | 0 |
| 2025-07 | 7 | 1 |
| 2025-08 | 14 | 0 |
| 2025-09 | null or fewer | |
| 2025-10 | 32 | 0 |
| 2025-11 | 18 | 2 |
| 2025-12 | 18 | 1 |
| 2026-01 | 7 | 1 |
| 2026-02 | 10 | 1 |
| 2026-03 | 22 | 0 |
| 2026-04 | 28 | 1 |
| 2026-05 | 11 | 0 |
| 2026-06 | null or fewer | |
| 2026-07 | 12 | 0 |
| 2026-08 | null or fewer | |
| 2026-09 | 10 | 0 |
Products
The products that kept showing up in Fortinet's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Fortinet.
- CVE-2026-84388A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to informa...9.6
- CVE-2026-84390A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access ...9.8
- CVE-2026-84392A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions...2.7
- CVE-2026-84391A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>6.5
- CVE-2026-22575An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, Fort...4.9
- CVE-2026-84393A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <inser...8.1
- CVE-2026-26084A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5...9.9
- CVE-2026-84385A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSO...5.4
- CVE-2026-84389A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or comma...3.1
- CVE-2026-84386A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector ...5.1
- CVE-2026-84387A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4....7.2
- CVE-2026-70468A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1...8.1
- CVE-2026-26035An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12...9.8
- CVE-2026-70467A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions,...3.8
- CVE-2026-70466A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all v...5.3
The record
- Peak rank
- #12 in Mar 2012
- Busiest month shown
- Jan 2025, 52 CVEs
- Months with a KEV entry
- 14 since Sep 2020
- Monthly snapshots
- 117 since 2005