Vendors
Ranked by risk — severity weighted, escalated for confirmed exploitation and exploit probability. Raw counts are shown alongside, because volume alone rewards vendors with weaker disclosure programs.
Risk-weighted, 2026
Security-category products only.
Who finds the vulnerabilities
All years. A vendor that finds its own bugs is doing something different from one whose bugs are found by outsiders — and raw counts cannot tell them apart.
Cisco
53% found in-house · of 680 attributed
- Vendor found 358
- Third party 322
Palo Alto Networks
26% found in-house · of 160 attributed
- Vendor found 41
- Third party 106
- Customer 13
- Unknown 3
Fortinet
- Not disclosed 353
Vendor totals, 2026
Switch year, or compare against the year before.
| Vendor | Risk | CVEs | Critical | Exploited | All products |
|---|---|---|---|---|---|
| Cisco | 667.6 | 113 | 14 | 9 | 191 |
| Fortinet | 599.5 | 85 | 9 | 6 | 88 |
| Palo Alto Networks | 207.0 | 52 | 1 | 2 | 52 |
“All products” includes non-security lines such as routing, switching and collaboration, which are excluded from the risk ranking.