Vendors

Ranked by risk — severity weighted, escalated for confirmed exploitation and exploit probability. Raw counts are shown alongside, because volume alone rewards vendors with weaker disclosure programs. Narrow to a single product line to compare firewalls against firewalls rather than whole portfolios.

risk is scored within the selected category

Risk-weighted, 2026

Firewall / NGFW

Who finds the vulnerabilities

All years. A vendor that finds its own bugs is doing something different from one whose bugs are found by outsiders — and raw counts cannot tell them apart.

Cisco

53% found in-house · of 833 attributed

  • Vendor found 445
  • Third party 388
  • Unknown 1
  • Not disclosed 220

Fortinet

56% found in-house · of 373 attributed

  • Vendor found 208
  • Third party 165
  • Not disclosed 2

Palo Alto Networks

32% found in-house · of 200 attributed

  • Vendor found 63
  • Third party 124
  • Customer 13
  • Unknown 21
  • Not disclosed 2

Check Point

  • Not disclosed 33

Vendor totals, 2026

Firewall / NGFW — set the year, category and comparison above.

Vendor Risk CVEs Critical Exploited All products
Cisco 462.1 84 10 4 463
Palo Alto Networks 155.1 30 1 2 90
Check Point 154.1 10 3 2 18
Fortinet 151.5 24 1 3 110

Risk, CVEs, critical and exploited counts are scoped to the selected category. “All products” is the vendor's whole portfolio for the year, including non-security lines such as routing, switching and collaboration, which never count toward risk. A CVE affecting products in two categories counts in full under each — it is a real vulnerability in both.