logo

Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections

ID: 39959dbb-741c-53f2-b701-6403e4e00076

STIX ID: report--39959dbb-741c-53f2-b701-6403e4e00076

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical zero-day in Cloudflare’s Web Application Firewall (WAF) allowed ACME HTTP-01 challenge path requests to bypass WAF rules and reach origin servers, enabling exposure of sensitive application data and framework-specific exploits; FearsOff researchers reported the issue to Cloudflare, which validated and patched the flaw on October 27, 2025, and stated there is no evidence of malicious exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.