Created on
02-06-2025
10:57 PM
Edited on
01-18-2026
06:38 AM
By
Jean-Philippe_P
| Description | This article describes the definition of 'Branches to fix' corresponding to the CVSS score. | |||||||||||||||||||||||
| Scope | All FortiOS. | |||||||||||||||||||||||
| Solution |
Fortinet PSIRT policy defines the 'Branches to fix' based on the CVSS score assigned to a specific vulnerability. The full PSIRT policy can be found via the following link: PSIRT Policy.
In the PSIRT policy, the branches to fix are highly dependent on the severity of the reported vulnerability:
As of January 2026, the FortiOS releases that have not reached the end of support date are as follows:
Reference: Fortinet Product Life Cycle.
Based on the information above, the categorization of the 'Branches to fix' is as follows:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.