Cloudflare Zero-Day Flaw Allows Attackers to Bypass Security and Access Any Host
ID: beae10d0-2230-5dde-bcec-4890e444534a
STIX ID: report--beae10d0-2230-5dde-bcec-4890e444534a
Feed Name: GBHackers
**Executive Summary:** A critical zero-day in Cloudflare's WAF allowed attackers to bypass customer-configured WAF rules by targeting the ACME certificate-validation path (/.well-known/acme-challenge/*), because the edge logic disabled WAF protections without verifying that the token matched an active challenge; proof-of-concept tests showed direct origin access exposing sensitive endpoints (e.g., Spring Boot actuator, Next.js SSR leaks, PHP LFI). FearsOff reported the issue on October 9, 2025 and Cloudflare deployed a fix on October 27, 2025, stating no evidence of malicious exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
