Skip to content
Cloudflare Patches Critical WAF Bypass Vulnerability

Cloudflare Patches Critical WAF Bypass Vulnerability

First seen 21 Jan 2026, 06:39 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Cloudflare addressed a critical zero-day vulnerability in its Web Application Firewall (WAF) that allowed attackers to bypass security rules and access protected origin servers. Discovered by FearsOff security researchers in October, the flaw stemmed from a logic error in the ACME certificate validation process. Cloudflare confirmed that no customer action was required to mitigate the issue.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (5)

Following this threat?

Track Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed