logo

Cloudflare Zero-Day Let Attackers Bypass WAF via ACME Certificate Validation Path

ID: 9bef235f-4623-5123-9d2d-068daeaa10a3

STIX ID: report--9bef235f-4623-5123-9d2d-068daeaa10a3

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A critical zero-day in Cloudflare’s ACME HTTP-01 validation logic allowed requests to the /.well-known/acme-challenge/* path to bypass customer Web Application Firewall (WAF) protections and be forwarded to origin servers without inspection. The flaw arose because Cloudflare disabled WAF protections for any ACME challenge path request without verifying the token belonged to an active certificate challenge for the specific hostname. Discovered by researchers on October 9, 2025 and disclosed by Cloudflare on October 13, 2025, Cloudflare updated its edge logic to only disable WAF when serving a valid hostname-specific ACME challenge response and stated it was unaware of any prior malicious exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.