Vendors

Ranked by risk — severity weighted, escalated for confirmed exploitation and exploit probability. Raw counts are shown alongside, because volume alone rewards vendors with weaker disclosure programs. Narrow to a single product line to compare firewalls against firewalls rather than whole portfolios.

risk is scored within the selected category

Risk-weighted, 2026

Firewall / NGFW

Who finds the vulnerabilities

All years. A vendor that finds its own bugs is doing something different from one whose bugs are found by outsiders — and raw counts cannot tell them apart.

Cisco

53% found in-house · of 834 attributed

  • Vendor found 445
  • Third party 389
  • Unknown 1
  • Not disclosed 220

Fortinet

56% found in-house · of 374 attributed

  • Vendor found 209
  • Third party 165
  • Not disclosed 2

Palo Alto Networks

32% found in-house · of 200 attributed

  • Vendor found 63
  • Third party 124
  • Customer 13
  • Unknown 21
  • Not disclosed 2

Check Point

  • Not disclosed 33

Vendor totals, 2026

Firewall / NGFW — set the year, category and comparison above.

Vendor Risk CVEs Critical Exploited All products
Cisco 248.0 67 4 1 464
Palo Alto Networks 155.3 30 1 2 90
Fortinet 149.7 23 1 3 111
Check Point 125.0 10 3 2 18

Risk, CVEs, critical and exploited counts are scoped to the selected category. “All products” is the vendor's whole portfolio for the year, including non-security lines such as routing, switching and collaboration, which never count toward risk. A CVE affecting products in two categories counts in full under each — it is a real vulnerability in both.