CVE-2025-55182 virtual patch enabled by default

ngwaf-announcementsadded

The virtual patch for CVE-2025-55182, released on December 2, 2025, which also addresses the vulnerabilities in CVE-2025-66478, is now enabled by default with immediate blocking for all Next-Gen WAF customers.

To disable this rule for your environment, follow the instructions in our guide to working with virtual patches.

Prior change: Protection from CVE-2025-55182 (React) and CVE-2025-66478 (Next.js)