Cloudflare Patches Critical WAF Bypass Vulnerability

Cloudflare Patches Critical WAF Bypass Vulnerability

First seen 21 Jan 2026, 06:39 UTC LinkedinThecyberexpressTheregisterScworld 88% similarity 21.0

Article Content

Browse articles
ThreatCluster

Cloudflare addressed a critical zero-day vulnerability in its Web Application Firewall (WAF) that allowed attackers to bypass security rules and access protected origin servers. Discovered by FearsOff security researchers in October, the flaw stemmed from a logic error in the ACME certificate validation process. Cloudflare confirmed that no customer action was required to mitigate the issue.

ThreatCluster AI How this analysis works

Community

Browse all →