Who?
Who actually uses FortiWeb though?
So many products, so little useful ones.
Fortinet has confirmed that another flaw in its FortiWeb web application firewall has been exploited as a zero-day and issued a patch, just days after disclosing a critical bug in the same product that attackers had found and abused a month earlier. The new bug, tracked as CVE-2025-58034, is an OS command injection …
More folks than you'd think. It's mostly used as default kit for smaller, regional ISP oriented SME type stuff.
Quite a few MSPs deploy Fortinet stuff as well.
Its like a lot of this sort of thing, you only really see it if you work for an MSP that deploys it. Its not The kind of thing you buy to exceed expectations is the kind of kit you buy to meet a minimum specification.
"They want slower than gigabit internet? Just whack a Fortinet on it then, no need to be fancy".
Fortinet isnt the only one either, there's quite a few players in the "how much margin can we find in £50" space.
Its the segment where Draytek and Mikrotik tend to rule...but for the customers reluctant to pay their prices because they're cheap.
5 PCs, a NAS (two disks, one dead) and Office 365. Blue office furniture. MD drives a silver C class Merc from 4 years ago...mid spec, cloth seats...calls the Fortinet box the "Internet fing". Probably a freight forwarder but also stores a lot of shit in the warehouse for £18 a square foot (its the going rate round here mate)...might be a local glazing / aircon / patio furniture company (year round innit, gotta diversificate mate). Goes on holiday to Dubai. Well thats what he tells you, he actually goes there for 2 days and spends 8 days on the way back in Benidorm. You can tell because he flies out of Heathrow (T3) but weirdly comes back in to Stansted.
You know...Fortinet customers.
Best to place the FortiWeb web application firewall behind another perimeter firewall.
FortiGate vs FortiWeb | Which Security Solution is Right for You?