Cloudflare patched a vulnerability in its ACME (Automatic Certificate Management Environment) HTTP-01 validation handling that could disable some Cloudflare WAF protections for requests to /.well-known/acme-challenge/*, potentially allowing traffic to reach otherwise protected origin servers. The issue was reported by FearsOff via Cloudflare’s bug bounty program after they observed that, in certain configurations where customers explicitly blocked broad access with WAF rules, requests sent to the ACME challenge directory could bypass those rules and be forwarded to the origin.
Independent testing described by the researchers showed that normal requests were blocked by Cloudflare as expected, while requests to the ACME challenge path elicited origin-generated responses (often application/framework 404 pages), indicating the request reached the backend. Cloudflare attributed the behavior to edge-network logic intended to avoid interfering with certificate issuance flows; when a request appeared related to ACME validation, some WAF features could be disabled and the request allowed through when it should have been blocked. Cloudflare stated the vulnerability has been mitigated, no customer action is required, and it is not aware of malicious exploitation.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Cloudflare published details of the vulnerability and its remediation, explaining the root cause, patch, and that it had no evidence of malicious exploitation. The disclosure stated customers did not need to take any action.
Cloudflare released a code change on 2025-10-27 so WAF protections are only disabled when a request matches a valid ACME HTTP-01 token for the specific hostname and Cloudflare has a challenge response to serve. Cloudflare said no customer action was required.
Cloudflare confirmed the researcher report and validated the vulnerability, determining that WAF features could be disabled for ACME-related requests even when the token did not belong to the requested hostname. Multiple sources place Cloudflare’s confirmation on 2025-10-13.
FearsOff researchers identified a logic flaw in Cloudflare’s handling of ACME HTTP-01 validation requests that could let traffic to `/.well-known/acme-challenge/*` bypass WAF protections and reach customer origin servers. They reported the issue through Cloudflare’s bug bounty/HackerOne program on 2025-10-09.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcethecyberexpress.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.