Virtual patches for CVEs

To help protect your web application against Common Vulnerabilities and Exposures (CVE), you can enable virtual patches. A virtual patch is a pre-constructed rule that targets a specific CVE. Once enabled, requests that meet the virtual patch's criteria are tagged with the appropriate CVE signal and then blocked or logged per your enablement specification. We announce new virtual patches through our changelog guide.

Enabling virtual patches using the Fastly control panel

From the Fastly control panel, you can enable CVE virtual patches from the Signals page and from workspace settings.

  1. Signals page
  2. Workspace settings
  1. Log in to the Fastly control panel.
  2. Go to Security > Next-Gen WAF > Signals.
  3. From the workspaces bar, click the menu Menu icon to the right of the workspace name and select a workspace.
  4. Click the Virtual Patches tab.
  5. Click the name of the virtual patch that you want to enable.
  6. Click Configuration and then Detections.
  7. Click the Status switch to the On position. Fastly tags and logs all requests matching the signal's criteria.
  8. Click the Thresholds tab.
  9. Click the Immediate blocking switch to the On position to immediately block all requests tagged with the virtual patch signal. Leave the switch in the Off position if you only want to log the requests.

Working with virtual patches using the Next-Gen WAF control panel

From the Next-Gen WAF control panel, you can enable virtual patches and subscribe to virtual patch release notifications.

Enabling virtual patches

The steps to enable a CVE virtual patch depend on the platform or packaged offering that you've purchased.

  1. Professional and Premier platforms or packaged offerings
  2. Essential platform

If you're on the Professional or Premier platform or have purchased the Security Core, Security Core Plus, or Security Total packaged offering, complete the following steps:

  1. Log in to the Next-Gen WAF control panel.
  2. From the Sites menu, select a site if you have more than one site.
  3. From the Rules menu, select Templated Rules.
  4. Click View to the right of the virtual patch rule you want to enable or edit.
  5. Click Configure and then Add trigger.
  6. Select the Block requests from an IP immediately if the CVE-YYYY-NNNNN signal is observed checkbox.
  7. Click Update rule.

Subscribing to virtual patch announcements

To receive an email when we release a new virtual patch, complete the following steps using the Next-Gen WAF control panel:

  1. Log in to the Next-Gen WAF control panel.
  2. From the corp navigation bar, click My Profile.
  3. In the Corp subscriptions section, select the Alert me when a new Virtual Patch for a CVE is available checkbox.