An Azure service that provides protection for web apps.
Hi @CHIU, Tony
There is no official percentage, and there can't be a meaningful one. The Top 10 are risk categories (249 CWEs total), while CRS 3.2 is a set of request signatures. Most categories are code and design flaws a WAF can't see.
Also, the current edition is Top 10:2025, there's no 2026 version.
Here's how CRS 3.2 maps to it:
- A05 Injection: strong. SQLi, XSS, RCE, LFI/RFI, protocol attacks. This is what CRS is built for.
- A02 Security Misconfiguration: partial. Protocol/method enforcement, scanner detection, Known CVE rules.
- A01 Broken Access Control: limited. Path traversal and some SSRF only. Authorization logic is invisible to a WAF.
- A07 Authentication Failures: limited. Session fixation only. Brute force needs Bot Manager and custom rate limits.
- A03, A04, A06, A08, A09, A10: not addressable by any WAF.
Summary for an audit: one category covered fully, three partially, six out of scope by design.
Two tips: on Application Gateway WAF v2, prefer DRS 2.1 over CRS 3.2 (adds Microsoft threat intel rules). And if auditors demand a number, map CRS rule CWE tags against OWASP's published CWE list per category. That gives a defensible figure for your exact config.
If this helped, please click Accept Answer so others can find it.
References: https://owasp.org/Top10/2025/ https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules