Starting today, Barracuda Vulnerability Remediation Service is integrated directly into WAF-as-a-Service. Using Vulnerability Remediation Service, you can:

  • Run scans on your applications.

  • View reports and statistics on the vulnerabilities found.

  • Automatically patch vulnerabilities in WAF-as-a-Service to mitigate them.

To get started, simply add the “Vulnerability Scanning” component in WAF-as-a-Service. For more information about Vulnerability Remediation Service, please see Barracuda Campus.

There are two current limitations to the integration:

  1. You cannot use Vulnerability Remediation Service to perform “bypass scans,” which bypass WAF-as-a-Service to scan the backend server directly. This option will be made available in approximately 7 days.

  2. Certain vulnerabilities cannot be patched by WAF-as-a-Service yet. These will show with a special message in Vulnerability Remediation Service. The list of vulnerabilities that cannot be remediated will shrink to zero over the next few weeks as we complete all the required features.