Coverage of OWASP 2026 Top 10 by Azure OWASP 3.2 managed rules

CHIU, Tony 0 Reputation points
2026-09-21T01:50:27.8133333+00:00

How much percentage and extent of Azure OWASP 3.2 managed rule controls covered the Top 10 OWASP 2026 https://top10.owasp.org/2025/

Azure Web Application Firewall

1 answer

Sort by: Most helpful
  1. Rukshan edirisinghe 910 Reputation points
    2026-09-21T04:00:22.04+00:00

    Hi @CHIU, Tony

    There is no official percentage, and there can't be a meaningful one. The Top 10 are risk categories (249 CWEs total), while CRS 3.2 is a set of request signatures. Most categories are code and design flaws a WAF can't see.

    Also, the current edition is Top 10:2025, there's no 2026 version.

    Here's how CRS 3.2 maps to it:

    • A05 Injection: strong. SQLi, XSS, RCE, LFI/RFI, protocol attacks. This is what CRS is built for.
    • A02 Security Misconfiguration: partial. Protocol/method enforcement, scanner detection, Known CVE rules.
    • A01 Broken Access Control: limited. Path traversal and some SSRF only. Authorization logic is invisible to a WAF.
    • A07 Authentication Failures: limited. Session fixation only. Brute force needs Bot Manager and custom rate limits.
    • A03, A04, A06, A08, A09, A10: not addressable by any WAF.

    Summary for an audit: one category covered fully, three partially, six out of scope by design.

    Two tips: on Application Gateway WAF v2, prefer DRS 2.1 over CRS 3.2 (adds Microsoft threat intel rules). And if auditors demand a number, map CRS rule CWE tags against OWASP's published CWE list per category. That gives a defensible figure for your exact config.

    If this helped, please click Accept Answer so others can find it.

    References: https://owasp.org/Top10/2025/ https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.