logo

Cloudflare Zero-Day Flaw Allows Attackers to Bypass Security and Access Any Host

ID: beae10d0-2230-5dde-bcec-4890e444534a

STIX ID: report--beae10d0-2230-5dde-bcec-4890e444534a

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive Summary:** A critical zero-day in Cloudflare's WAF allowed attackers to bypass customer-configured WAF rules by targeting the ACME certificate-validation path (/.well-known/acme-challenge/*), because the edge logic disabled WAF protections without verifying that the token matched an active challenge; proof-of-concept tests showed direct origin access exposing sensitive endpoints (e.g., Spring Boot actuator, Next.js SSR leaks, PHP LFI). FearsOff reported the issue on October 9, 2025 and Cloudflare deployed a fix on October 27, 2025, stating no evidence of malicious exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.