Report | WAF Comparison Project, 2026 | Check Point Software

WAF Comparison Project 2026

Introduction

This article describes the results of our annual WAF Efficacy comparison. For the third year in a row, we tested leading WAF solutions in rigorous, real-world conditions, triggering both malicious and legitimate web requests to measure exactly how well - or how poorly - these vendors protect modern applications. While previous years focused on the decline of ModSecurity and updates to the OWASP Core Rule Set, 2025 marked a shift toward exposing the architectural limitations of traditional WAFs. As vulnerabilities become more complex, the limitations of legacy, signature-based engines are becoming impossible to ignore. This year’s test introduces a new focus on Padding Evasion - inspired by the critical React2Shell vulnerability - and highlights how fixed-buffer inspection limits are leaving modern applications exposed.

The Core Challenge: Security vs. Detection

The two most important parameters when selecting a Web Application Firewall remain:

A very comprehensive data set was used to test the products:

Loyal to the spirit of open-source, we provide in this GitHub repository all the details of the testing methodology, testing datasets, and open-source tools that are required to validate and reproduce this test and welcome the community's feedback.

Products Tested and Results

This year's test was conducted in December 2025, and compared the following popular WAF solutions:

The test reveals significant differences in product performance. For example:

To provide security and allow minimal administration overhead, the optimal WAF solution should strike a balance, exhibiting high performance on both Security Quality and Detection Quality, aptly represented by a measurement called Balanced Accuracy - an arithmetic mean of the True Positives and True Negatives rates.