All glossary terms
Glossary

Virtual patching

Virtual patching is blocking the exploitation of a known vulnerability at the WAF or edge, before the application code itself is fixed.

Fixing a vulnerability in code can take days or weeks: development, testing, release. Attackers often start exploiting a new CVE within hours. A virtual patch is a targeted edge rule that blocks the exploit pattern in the meantime.

Good virtual patches are narrow, so they stop the exploit without blocking normal use of the same endpoint, and they're removed once the real fix ships.

Where Huskeys fits

Huskeys generates and deploys virtual patches automatically, scored and tracked until the code fix lands.

Related terms

Further reading