Post-quantum encryption for Cloudflare IPsec is generally available

2026-05-04T07:24:05Z07cb519e6d51ee8b1e21002932a694a340be248651dd877ab442ab5b2b2082a3
ACME validationAI SecurityAPI tokensCloudflare RadarDDoSIPsecMCPML-KEMManaged OAuthMatrix homeserverOAuthPingoraWorkers VPCclient-side securitygraph neural networksleast-privilegepost-quantumpost-quantum-roadmapquantum-cryptographyrequest smugglingshadow AI discoveryvulnerability scanner

What happened

Collection of Cloudflare security blog posts (Jan–Apr 2026) covering major product security launches, research, and vulnerability disclosures. Key items: general availability of post‑quantum IPsec using hybrid ML‑KEM (interoperable with Cisco and Fortinet) and a roadmap targeting full post‑quantum security by 2029; GA of AI Security for Apps and expanded discovery for shadow AI; new developer security controls (scannable API tokens, resource‑scoped permissions, OAuth visibility, Managed OAuth for Access using RFC 9728); expansion of Client‑Side Security and a new Web/API vulnerability scanner;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
07cb519e6d51ee8b1e21002932a694a340be248651dd877ab442ab5b2b2082a3
Enrichment time
2026-05-04T07:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Post-quantum encryption for Cloudflare IPsec is generally available · Baitaphish