Post-quantum encryption for Cloudflare IPsec is generally available

2026-05-05T19:24:11Za654e0b756fc4662dbe70a079aee1a995b70d2972ffda57cd500dbeb289fe79a
ACMEAI-securityDDoSIPsecOAuthaccount-abusecertificate-validationclient-side-securitycloudflare-radarhybrid-ML-KEMleast-privilegelog-explorermanaged-oauthmatrixpingorapost-quantumpost-quantum-cryptographyrequest-smugglingscannable-api-tokensvulnerability-disclosurevulnerability-scannerworkers-vpc

What happened

Collection of Cloudflare security announcements (Mar–Apr 2026) covering product GA/betas, new defenses, disclosures, and roadmap updates. Highlights: GA support for post-quantum IPsec via hybrid ML-KEM (interoperable with Cisco/Fortinet) and a company-wide push to target full post-quantum security by 2029; disclosure and fixes for request smuggling in Pingora OSS (fixed in Pingora 0.8.0) and mitigation of an ACME certificate-validation vulnerability; GA/EA launches including AI Security for Apps, Client-Side Security, Account Abuse Protection, Managed OAuth for Access (RFC 9728) and resource‑/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
a654e0b756fc4662dbe70a079aee1a995b70d2972ffda57cd500dbeb289fe79a
Enrichment time
2026-05-05T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Post-quantum encryption for Cloudflare IPsec is generally available · Baitaphish