Vendors

Ranked by risk — severity weighted, escalated for confirmed exploitation and exploit probability. Raw counts are shown alongside, because volume alone rewards vendors with weaker disclosure programs.

Risk-weighted, 2026

Security-category products only.

Who finds the vulnerabilities

All years. A vendor that finds its own bugs is doing something different from one whose bugs are found by outsiders — and raw counts cannot tell them apart.

Cisco

53% found in-house · of 680 attributed

  • Vendor found 358
  • Third party 322

Palo Alto Networks

26% found in-house · of 160 attributed

  • Vendor found 41
  • Third party 106
  • Customer 13
  • Unknown 3

Fortinet

  • Not disclosed 353

Vendor totals, 2026

Switch year, or compare against the year before.

security categories only
Vendor Risk CVEs Critical Exploited All products
Cisco 667.6 113 14 9 191
Fortinet 599.5 85 9 6 88
Palo Alto Networks 207.0 52 1 2 52

“All products” includes non-security lines such as routing, switching and collaboration, which are excluded from the risk ranking.