Compare vendors
Like-for-like comparison within the same product category — firewall against firewall. Defaults to risk-weighted exposure rather than raw volume; switch to counts, pick a year, choose which vendors to include, and optionally compare against the year before. Click any bar for the CVEs behind it.
| Category | Risk (2026) | CVEs | Exploited |
|---|---|---|---|
| Firewall / NGFW | 922.7 | 148 | 11 |
| Endpoint / EDR | 278.6 | 35 | 2 |
| SASE / SSE / Secure Web | 213.7 | 50 | 2 |
| VPN & Remote Access | 20.0 | 10 | 0 |
| Email Security | 93.0 | 10 | 1 |
| Identity / IAM / MFA | 472.6 | 84 | 2 |
| SIEM & Log Management | 706.2 | 176 | 2 |
| Threat Detection & Sandbox | 236.5 | 32 | 2 |
| Web & Application Security | 101.7 | 12 | 1 |
| Cloud Security | 57.3 | 8 | 0 |
| OT / IoT Security | 12.1 | 6 | 0 |
| Network & Security Management | 733.4 | 84 | 10 |
| Routing & Switching | 277.3 | 63 | 1 |
| Other Products | 244.6 | 59 | 2 |
Table view
N/A means that vendor ships no product in the category, so there is nothing to count. It is not the same as 0, which means they compete there and had no CVEs that year.
Categories where every selected vendor has zero are hidden. Non-security categories — routing, collaboration — are excluded by default so a broad-portfolio vendor is not compared against a pure-play one on products that are not security. See methodology.