Alerts
Cloudflare WAF Zero-Day Allowed Attackers to Bypass Security Controls via ACME Challenge Path
A critical zero-day vulnerability in Cloudflare's Web Application Firewall (WAF) allowed attackers to bypass security controls and directly access protected origin servers. Security researchers at FearsOff discovered that requests targeting the /.well-known/acme-challenge/ directory could reach origin servers even when WAF rules explicitly blocked all