Post-quantum encryption for Cloudflare IPsec is generally available

2026-05-02T07:24:06Za607934c92bdca4288f17e7d11176b9d791d2a817ff12704cec609ad5f48e4a5
31.4 TbpsACME validationAI Security for AppsAPI securityASPAAccount Abuse Protection','Cloudy','LLM','Workers VPCCiscoClient-side securityCloudflare RadarDDoSFortinetIPsecLog ExplorerMCPML-KEMManaged OAuthPingoraRFC 9728hybrid KEMkey transparencypost-quantumrequest smugglingresource-scoped permissionsscannable API tokensvulnerability scanner

What happened

Collection of Cloudflare security blog posts (Nov 2025–Apr 2026) covering multiple product and research updates. Notable security items: Pingora OSS had request-smuggling vulnerabilities that were fixed in Pingora 0.8.0; a vulnerability in Cloudflare’s ACME validation automation was identified and mitigated; Cloudflare announced general-availability support for post-quantum IPsec using a hybrid ML‑KEM (interoperable with Cisco and Fortinet) and set a 2029 target for full post‑quantum security. Additional posts include GA releases and features for Managed OAuth (RFC 9728), scannable API tokens,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
a607934c92bdca4288f17e7d11176b9d791d2a817ff12704cec609ad5f48e4a5
Enrichment time
2026-05-02T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.