Report | WAF Comparison Project, 2026 | Check Point Software
WAF Comparison Project 2026
Introduction
This article describes the results of our annual WAF Efficacy comparison. For the third year in a row, we tested leading WAF solutions in rigorous, real-world conditions, triggering both malicious and legitimate web requests to measure exactly how well - or how poorly - these vendors protect modern applications. While previous years focused on the decline of ModSecurity and updates to the OWASP Core Rule Set, 2025 marked a shift toward exposing the architectural limitations of traditional WAFs. As vulnerabilities become more complex, the limitations of legacy, signature-based engines are becoming impossible to ignore. This year’s test introduces a new focus on Padding Evasion - inspired by the critical React2Shell vulnerability - and highlights how fixed-buffer inspection limits are leaving modern applications exposed.
The Core Challenge: Security vs. Detection
The two most important parameters when selecting a Web Application Firewall remain:
- Security Quality (True Positive Rate) - the WAF's ability to correctly identify and block malicious requests is crucial in today's threat landscape. It must preemptively block zero-day attacks as well as effectively tackle known attack techniques utilized by hackers.
- Detection Quality (False Positive Rate) – aka the WAF's ability to correctly allow legitimate requests is also critical because any interference with these valid requests could lead to significant business disruption and an increased workload for administrators as much tuning is required.
A very comprehensive data set was used to test the products:
- 1,040,242 legitimate HTTP requests from 692 real websites in 14 categories
- 74,284 malicious payloads from a broad spectrum of commonly experienced attack vectors
Loyal to the spirit of open-source, we provide in this GitHub repository all the details of the testing methodology, testing datasets, and open-source tools that are required to validate and reproduce this test and welcome the community's feedback.
Products Tested and Results
This year's test was conducted in December 2025, and compared the following popular WAF solutions:
- Microsoft Azure WAF – OWASP CRS 3.2 Ruleset
- AWS WAF – AWS Managed Ruleset
- AWS WAF – AWS Managed Ruleset and F5 Ruleset
- CloudFlare WAF – Managed and OWASP Core Rulesets
- F5 NGINX App Protect WAF – Default Profile
- F5 NGINX App Protect WAF – Strict Profile
- NGINX ModSecurity – OWASP CRS 4.20.0 (updated from previously tested version 4.3.0)
- CloudGuard WAF – Default Configuration (High Confidence)
- CloudGuard WAF – Critical Confidence Configuration
- F5 BIG-IP Advanced WAF – Rapid Deployment Policy
- Fortinet FortiWeb – Default Configuration
- Google Cloud Armor – Preconfigured ModSecurity Rules (Sensitivity level 2)
- Barracuda WAF – Default Configuration (new vendor added this year)
The test reveals significant differences in product performance. For example:
- Azure WAF offers very high Security Quality (97.537%) but has an extremely high false positive rate of 54.412%, potentially blocking legitimate requests and disrupting normal operations. These results suggest that some products may pose security risks due to missed detections or require substantial tuning to balance security effectiveness with usability.
To provide security and allow minimal administration overhead, the optimal WAF solution should strike a balance, exhibiting high performance on both Security Quality and Detection Quality, aptly represented by a measurement called Balanced Accuracy - an arithmetic mean of the True Positives and True Negatives rates.