URL has been copied successfully!
Cloudflare Zero-Day Let Attackers Bypass WAF via ACME Certificate Validation Path
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Cloudflare Zero-Day Let Attackers Bypass WAF via ACME Certificate Validation Path

A critical zero-day vulnerability in Cloudflare exposed a fundamental weakness in how security exceptions are handled at scale. The flaw allowed attackers to bypass Cloudflare’s Web Application Firewall (WAF) entirely and directly access protected origin servers by abusing a certificate validation endpoint. The issue was not caused by customer misconfiguration, but by a logic error in Cloudflare’s edge processing of ACME certificate validation traffic.

First seen on thecyberexpress.com

Jump to article: thecyberexpress.com/cloudflare-zero-day-waf-bypass-acme/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link