Quite simply, as prodigious as the purveyors of malware are, the effort to detect new malware and address it means each NGFW provider must update their software individually.
While it is possible for malware protection within a computer network to do this work, the best practice is to detect and isolate a problem at the network boundary using a NGFW before it can reach the computer network.