Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections
ID: 39959dbb-741c-53f2-b701-6403e4e00076
STIX ID: report--39959dbb-741c-53f2-b701-6403e4e00076
Feed Name: cybersecurityNews.com
Threat Score
A critical zero-day in Cloudflare’s Web Application Firewall (WAF) allowed ACME HTTP-01 challenge path requests to bypass WAF rules and reach origin servers, enabling exposure of sensitive application data and framework-specific exploits; FearsOff researchers reported the issue to Cloudflare, which validated and patched the flaw on October 27, 2025, and stated there is no evidence of malicious exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
