Fortinet
CPE vendor key: fortinet ·
371 CVEs published in the last 24 months.
CVEs (365 d)
169
▼ -8 vs prior 30d
Avg CVSS (365 d)
6.85
over 169 CVEs
Avg EPSS pct (365 d)
0.34
higher = more likely exploited
KEV hit rate (365 d)
4.1%
7 of 169 added to CISA KEV
LLM-credited CVEs
0
Monthly CVE volume — last 24 months
Each point is one calendar month. Bars in the
severity card to the right slice the same volume by CVSS band.
Severity mix
Stacked by CVSS band (Critical / High / Medium /
Low) using the best available metric per CVE.
Top affected products (24 mo)
89
56
46
46
42
28
27
26
20
18
Distinct CVEs that include each product in their
CPE configuration.
Top CWEs (24 mo)
39
25
24
20
16
16
14
12
11
9
Distinct CVEs assigned each weakness.
Recent CISA KEV adds (last 12 months)
| Added | CVE | Product | KEV name |
|---|---|---|---|
| 2026-04-13 | CVE-2026-21643 | FortiClient EMS | Fortinet FortiClient EMS SQL Injection Vulnerability |
| 2026-04-06 | CVE-2026-35616 | FortiClient EMS | Fortinet FortiClient EMS Improper Access Control Vulnerability |
| 2026-01-27 | CVE-2026-24858 | Multiple Products | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability |
| 2025-12-16 | CVE-2025-59718 | Multiple Products | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability |
| 2025-11-18 | CVE-2025-58034 | FortiWeb | Fortinet FortiWeb OS Command Injection Vulnerability |
| 2025-11-14 | CVE-2025-64446 | FortiWeb | Fortinet FortiWeb Path Traversal Vulnerability |
| 2025-07-18 | CVE-2025-25257 | FortiWeb | Fortinet FortiWeb SQL Injection Vulnerability |
Filtered to KEV rows where the CISA vendor name matches this vendor,
to drop cross-OS noise (e.g. third-party Windows apps that CPE-map to
Microsoft).
LLM-credited CVEs from this vendor
No LLM-credited CVEs for this vendor yet.
From
mythos_attributed_cves: CVEs whose NVD description
or vendor advisory credits an LLM-assisted discovery. Confidence is
high for every row.
Generated 19 June 2026 13:18 UTC <span class="time-ago" data-iso="2026-06-19T13:18:30Z"></span>.