Summary
- F5’s September expansion combines application-specific analysis, threat context and virtual patching. Some capabilities are available now; anomaly detection and agentic threat intelligence are still rolling out.
- The commercial link is between a scan finding and an enforceable rule. That rule can reduce exposure without repairing the vulnerable code, so validation and eventual relaxation remain part of the work.
A scan report can move from a security queue to a development queue without changing what an exposed application will accept. F5 wants to shorten the distance between that finding and a decision in the live request path.
In its 1 September announcement, the company describes an expansion of runtime protection around F5 WAF for Distributed Cloud. Application-specific anomaly detection and agentic threat intelligence add context to inline risk scoring. Virtual patching then applies scoped protection while a permanent software fix goes through development, testing and change control. The pitch is not simply another list of vulnerabilities: it is a route from evidence to enforcement.
Availability is uneven. F5 says its new AI-powered WAF capabilities on Distributed Cloud, virtual patching and the integration of Web App Scanning with WAF for BIG-IP are available. It separately says anomaly detection and agentic threat intelligence are rolling out, with broader availability over coming months. Buyers should not read that as every feature already enabled everywhere.
Nor is the scan-to-policy connection entirely new. A June implementation article describes exporting findings from Web App Scanning and importing them into BIG-IP Advanced WAF, using an existing or new policy and selecting the vulnerability domains to protect. The September expansion builds on that operating surface. It does not establish that every finding becomes a blocking rule without human choice.
The quality of the finding depends on what the scanner reaches. F5’s September technical-marketing explanation introduces AI-assisted interaction with forms to explore deeper application workflows. Yet the current app-definition documentation still makes the boundary concrete: the entry URL and test-user credentials define an app; other required hostnames must be included in the allowlist. By default, resources outside the entry hostname are not tested. A wider-looking report is therefore not, by itself, proof of coverage across every role and service.
That boundary is commercial as well as technical. Scan is priced by apps scanned each month. Repeated tests and different Test Profiles for the same app do not count as additional unique apps. This creates room to validate a configured application repeatedly without confusing more test runs with a larger billed application estate; it says nothing about an undisclosed total customer bill.
F5’s own June guidance also gives the essential limit: a virtual patch does not remove the underlying vulnerability, and incomplete rules can be bypassed. Logs, legitimate-traffic checks and continued scanning inform tuning and when controls may be relaxed after a comprehensive fix. The release’s efficacy claims come from internal testing, not independent production evidence. The defensible opportunity is a managed path from finding to temporary control—not the disappearance of remediation work.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

