Security incident on record — Multiple high-severity CVEs in FortiOS (2022-2025) — actively exploited by threat actors; Fortinet improved patch velocity
▪ Editorial verdict
Fortinet FortiGate has 50 plus percent global NGFW market share and the highest throughput per dollar in the category, backed by custom ASIC hardware that delivers full inspection performance that competitors match only at significantly higher cost. The six million FortiGate deployments globally reflect a market that has validated its value at every scale from branch office to hyperscale data centre.
The CVE history requires direct attention. Multiple high-severity FortiOS vulnerabilities have been actively exploited by threat actors between 2022 and 2025, and CISA has repeatedly featured FortiGate in its Known Exploited Vulnerabilities catalog. Fortinet patches consistently and the vulnerabilities reflect the reality of running the world's most deployed internet-facing security appliance. Buyers must commit to a rigorous patch management process as a condition of any FortiGate deployment.
The verdict: Fortinet FortiGate is right for organisations that need the best throughput per dollar across all security services with the broadest SD-WAN integration. Organisations must maintain rigorous patch discipline as a non-negotiable operational requirement.
Firewall + IPS + AV + URL filtering + application control + sandboxing + SD-WAN all in one FortiOS platform. Scored 5 for the broadest integrated security services stack. 6 million FortiGates deployed globally.
Scored 4 rather than 5 because Gartner explicitly notes the high number and severity of exploitable CVEs in FortiOS as a documented concern. Detection quality is good but the vulnerability surface is a risk.
Sources: Gartner HMF MQ 2025, CISA Known Exploited Vulnerabilities catalog
OPERATIONSStrong
Throughput under load
5 / 5
Highest real-world throughput of any NGFW — custom security processing units (SPUs) maintain performance with full security inspection enabled. Scored 5.
Sources: NSS Labs, Fortinet NP7 documentation
Policy management UX
3 / 5
Scored 3 because centralised management requires FortiManager (separate product) and FortiAnalyzer for logging — the UI split across products is a documented complexity.
Sources: G2 reviews, Gartner Peer Insights
ANALYTICSStrong
Traffic & threat visibility
4 / 5
Good application-level visibility and user identity mapping. Scored 4 because FortiAnalyzer is required for full traffic visibility — not included by default.
Sources: Fortinet documentation
TRUST & ECOSYSTEMStrong
Scalability & HA
5 / 5
Supports clustering up to 4-node active-active HA. Handles carrier-grade deployments. Scored 5 for proven scalability.