I met an experienced network engineer/executive recently in the financial sector and he said he would never use Fortinet firewalls due to the amount of CVE's. As a long time Fortinet customer, I'd love to hear your thoughts.
I’ve heard that many times before, but it’s not the whole story.
Fortinet ends up with a lot of CVEs because the platform does so much.
It includes NGFW, VPN, SD-WAN, proxy features, IPS, ZTNA, wireless and more. The more features a vendor ships, the larger the attack surface becomes, and naturally the higher the CVE count . That doesn’t automatically mean the product is insecure.
What really matters is how fast a vendor responds and Fortinet is usually quick with patches and clear PSIRT advisories. Every major firewall vendor has had serious vulnerabilities at one point or another, whether it’s Palo Alto, Cisco, Check Point or Juniper. None of them are immune.
In practice, FortiGate tends to be as secure and stable as the way it’s deployed. Staying on a supported firmware branch, patching regularly, enabling only what you actually use and following proper design and segmentation principles make a much bigger difference than the raw number of CVEs.
If Fortinet has served you well so far, I wouldn’t let the CVE count alone sway you.
| User | Count |
|---|---|
| 2803 | |
| 1425 | |
| 812 | |
| 750 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.