Default WAF Rules Inadequate Against Major CVE Exploits

Default WAF Rules Inadequate Against Major CVE Exploits

First seen 18 Dec 2025, 15:57 UTC BetanewsScworld 29.9

Article Content

Browse articles
ThreatCluster

A study by Miggo Security reveals that default web application firewall (WAF) rules fail to block over 52% of major CVE exploits. The analysis, which tested more than 360 CVEs published between January 2024 and October 2025, indicates that tailored AI rules can mitigate over 91% of these vulnerabilities. The findings highlight significant gaps in the effectiveness of leading WAF solutions.