Vendors
Ranked by risk — severity weighted, escalated for confirmed exploitation and exploit probability. Raw counts are shown alongside, because volume alone rewards vendors with weaker disclosure programs. Narrow to a single product line to compare firewalls against firewalls rather than whole portfolios.
Risk-weighted, 2026
Firewall / NGFW
Who finds the vulnerabilities
All years. A vendor that finds its own bugs is doing something different from one whose bugs are found by outsiders — and raw counts cannot tell them apart.
Cisco
53% found in-house · of 833 attributed
- Vendor found 445
- Third party 388
- Unknown 1
- Not disclosed 220
Fortinet
56% found in-house · of 373 attributed
- Vendor found 208
- Third party 165
- Not disclosed 2
Palo Alto Networks
32% found in-house · of 200 attributed
- Vendor found 63
- Third party 124
- Customer 13
- Unknown 21
- Not disclosed 2
Check Point
- Not disclosed 33
Vendor totals, 2026
Firewall / NGFW — set the year, category and comparison above.
| Vendor | Risk | CVEs | Critical | Exploited | All products |
|---|---|---|---|---|---|
| Cisco | 462.1 | 84 | 10 | 4 | 463 |
| Palo Alto Networks | 155.1 | 30 | 1 | 2 | 90 |
| Check Point | 154.1 | 10 | 3 | 2 | 18 |
| Fortinet | 151.5 | 24 | 1 | 3 | 110 |
Risk, CVEs, critical and exploited counts are scoped to the selected category. “All products” is the vendor's whole portfolio for the year, including non-security lines such as routing, switching and collaboration, which never count toward risk. A CVE affecting products in two categories counts in full under each — it is a real vulnerability in both.