Post-quantum encryption for Cloudflare IPsec is generally available

2026-05-04T19:24:16Z08f1267a16b7dc3b28da71b9c0f901729cb67bc805163f9004e1c837bf65355c
2029 targetACME validationAI securityClient-side securityCloudflare RadarDDoSIPsecLog ExplorerMCPManaged OAuthOAuth RFC 9728PingoraPingora 0.8.0Workers VPCcertificate validationhybrid ML-KEMpatchpost-quantumquantum roadmaprequest smugglingresource-scoped permissionsscannable API tokensshadow AIvulnerability disclosurevulnerability scanner

What happened

A collection of Cloudflare security blog posts covering product launches, roadmap updates, and vulnerability disclosures. Highlights include GA support for post-quantum IPsec (hybrid ML‑KEM) with interoperability tested against Cisco and Fortinet, a moved target for full post‑quantum security to 2029, GA releases for AI Security for Apps and other developer security features (scannable API tokens, resource‑scoped permissions, Managed OAuth for Access), expanded Client‑Side Security detection, a new Web/API vulnerability scanner, and visibility/analytics updates in Radar and Log Explorer. Two (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
08f1267a16b7dc3b28da71b9c0f901729cb67bc805163f9004e1c837bf65355c
Enrichment time
2026-05-04T19:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.