Virtual patch advisories
Tuning can show a “Virtual patch available” card. It names a threat class and a managed rule group that can watch that class in count. You click Add in count mode.
What the card is
A managed rule group can watch this class in count. You click Add in count mode. A rule that is already on stays as it is. Nothing here blocks on its own.
The catalog version on the card is 2026.10.1. It is a fixed list in the product, not a live feed and not a model. Adding a class means editing this catalog in a release. The card does not say the site is vulnerable, and it does not say the site is patched.
A class with a sampled request, a counted category, or a platform hint is marked Relevant. With no signal, the class is a general advisory and only shows when its rule group is off. It is not shown as “you are affected.”
If the group is already on, the card says so: already in count, or already in block. Add does not change a group that is already on. Nothing on the card blocks on its own.
Classes in this catalog
| Class | What the card says | Group you can add in count |
|---|---|---|
| Log4Shell-style JNDI strings | JNDI lookup strings in a header, query, or path. | Known exploits |
| Spring4Shell | Class-loader probes against Spring-style request binding. | Known exploits |
| Drupalgeddon-style form API probes | Form API arrays such as a render callback on a user form. | PHP application attacks |
| WordPress plugin and xmlrpc probes | Plugin paths and xmlrpc calls used to look for weak plugins. | WordPress protection |
| Citrix and Fortinet path traversal probes | Traversal toward Citrix gateway paths or Fortinet SSL-VPN language files. | Known exploits |
| Shellshock | A shell function prefix in a header or query, the Shellshock shape. | Unix / POSIX exploits |