Cloudflare Zero-day: Accessing Any Host Globally

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A zero-day vulnerability in Cloudflare's WAF allowed attackers to bypass security rules and access origin servers globally through the /.well-known/acme-challenge/ path. The vulnerability exploited the ACME HTTP-01 certificate validation mechanism, exposing protected origins despite WAF protections. Cloudflare has since patched

1m read time From fearsoff.org
Post cover image

Sort: