Virtual patch advisories

Tuning can show a “Virtual patch available” card. It names a threat class and a managed rule group that can watch that class in count. You click Add in count mode.

What the card is

A managed rule group can watch this class in count. You click Add in count mode. A rule that is already on stays as it is. Nothing here blocks on its own.

The catalog version on the card is 2026.10.1. It is a fixed list in the product, not a live feed and not a model. Adding a class means editing this catalog in a release. The card does not say the site is vulnerable, and it does not say the site is patched.

A class with a sampled request, a counted category, or a platform hint is marked Relevant. With no signal, the class is a general advisory and only shows when its rule group is off. It is not shown as “you are affected.”

If the group is already on, the card says so: already in count, or already in block. Add does not change a group that is already on. Nothing on the card blocks on its own.

Classes in this catalog

Catalog 2026.10.1
ClassWhat the card saysGroup you can add in count
Log4Shell-style JNDI stringsJNDI lookup strings in a header, query, or path.Known exploits
Spring4ShellClass-loader probes against Spring-style request binding.Known exploits
Drupalgeddon-style form API probesForm API arrays such as a render callback on a user form.PHP application attacks
WordPress plugin and xmlrpc probesPlugin paths and xmlrpc calls used to look for weak plugins.WordPress protection
Citrix and Fortinet path traversal probesTraversal toward Citrix gateway paths or Fortinet SSL-VPN language files.Known exploits
ShellshockA shell function prefix in a header or query, the Shellshock shape.Unix / POSIX exploits

Related guides

More in this section