Cloudflare Zero-Day Let Attackers Bypass WAF via ACME Certificate Validation Path
ID: 9bef235f-4623-5123-9d2d-068daeaa10a3
STIX ID: report--9bef235f-4623-5123-9d2d-068daeaa10a3
Feed Name: The Cyber Express
A critical zero-day in Cloudflare’s ACME HTTP-01 validation logic allowed requests to the /.well-known/acme-challenge/* path to bypass customer Web Application Firewall (WAF) protections and be forwarded to origin servers without inspection. The flaw arose because Cloudflare disabled WAF protections for any ACME challenge path request without verifying the token belonged to an active certificate challenge for the specific hostname. Discovered by researchers on October 9, 2025 and disclosed by Cloudflare on October 13, 2025, Cloudflare updated its edge logic to only disable WAF when serving a valid hostname-specific ACME challenge response and stated it was unaware of any prior malicious exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
