For most organizations, the honest answer is: nobody knows for sure. Do you even know that the product FortiWeb exists? Real question.
The list in Fortinet’s product portfolio is never ending : FortiWeb, FortiGate, FortiProxy, FortiCASB, FortiManager, FortiAnalyzer, FortiNAC, FortiMail, FortiSIEM, FortiSandbox, FortiVoice (?!)… Each product has multiple major versions, minors, patches, and hotfixes. They all have their own web interfaces, their own FortiOS version, their own administrative interfaces/port.
How do you avoid scrambling every time a new critical Fortinet vulnerability appears : when all you have at first is a tweet, a few unverified GitHub exploits, and a flood of rushed blog posts?