This brings back memories. At this point itโs probably an esoteric reference even. ๐
Repeat after me:
WAF are not a fix for vulnerabilities.
WAF are not a fix for vulnerabilities.
WAF are not a fix for vulnerabilities.
---
Had to report a critical vuln to someone and the response was an update WAF policy as the solution.
It happens, but the context I cannot elaborate on here is that this situation is particularly disappointing.