Post-quantum encryption for Cloudflare IPsec is generally available

2026-05-01T07:24:14Z6d477c94281b25b2ddd9e831acd341977a47292eef1764463b809c1450b9b4b6
2029acmeacme-validationai-gatewayapi-tokensciscoclient-side-securitycloudflarefortinetgraph-neural-networkshybrid-keminteroperabilityipsecllm-detectionmanaged-oauthmanaged-oauth-for-accessmcpml-kempingorapingora-0.8.0post-quantumpost-quantum-roadmaprequest-smugglingresource-scoped-permissionsrfc-9728

What happened

Collection of Cloudflare security and product announcements (Jan–Apr 2026). Key items: Post‑quantum IPsec is GA using a hybrid ML‑KEM (interoperable with Cisco and Fortinet) and Cloudflare moved its target for full post‑quantum security to 2029; disclosures and fixes for software vulnerabilities (request‑smuggling in Pingora OSS fixed in Pingora 0.8.0; an ACME validation/path vulnerability was identified and mitigated); new and GA security offerings including Managed OAuth for Access (RFC 9728 support), scannable API tokens and resource‑scoped permissions, Account Abuse Protection (EA), AI‑or‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
6d477c94281b25b2ddd9e831acd341977a47292eef1764463b809c1450b9b4b6
Enrichment time
2026-05-01T07:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Post-quantum encryption for Cloudflare IPsec is generally available · Baitaphish