• News/
  • https://www.theregister.com/2026/01/20/cloudflare_fixes_acme_validation/

Cloudflare whacks WAF bypass bug that opened side door for attackers

The Register
·
Jessica Lyons
·
Published Jan 20, 2026
·
Updated

Cloudflare has fixed a flaw in its web application firewall (WAF) that allowed attackers to bypass security rules and directly access origin servers, which could lead to data theft or full server takeover. FearsOff security researchers reported the bug in October through Cloudflare's bug bounty program, and the CDN says it has patched the vulnerability in its ACME (Automatic Certificate Management Environment) validation logic with no action required from its customers. ACME is a protocol that certificate authorities and services like Cloudflare use to automate the issuance, renewal, and revocation of SSL/TLS certificates. It uses challenges to prove domain ownership before issuing a security certificate, and this is typically done via an HTTP-01 challenge that checks for a validation token at the HTTP path following this format: http://{customer domain}/.well-known/acme-challenge/{token value}. In its report, the cyber-threat hunting firm likens a WAF to the front door and ACME to a hallway that should only be used by a certificate robot to verify domain ownership. When configured correctly, a WAF can help let expected validation traffic through while filtering out many malicious requests, including automated bots. "A certificate robot's hallway should never become a side door," the FearsOff researchers wrote. The "side door" in this case was caused by a logic flaw in how Cloudflare processed some ACME challenge requests. "Previously, when Cloudflare was serving a HTTP-01 ch...

Read full article

Affected Software

1 affected component
Cloudflare ACME=not specified
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerability was fixed by Cloudflare?

Cloudflare fixed a flaw in its web application firewall (WAF) that allowed attackers to bypass security rules.

2

What were the potential consequences of the WAF bypass bug?

The WAF bypass bug could have led to data theft or complete server takeover.

3

Which specific product was affected by this security issue?

The affected product is Cloudflare ACME.

4

How did the security vulnerability impact users?

The vulnerability exposed users to unauthorized access to their origin servers.

5

Who identified the flaw in Cloudflare's firewall?

The flaw was identified by the security researcher FearsOff.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203