Cloudflare Client-Side Security: smarter detection, now open to everyone

2026-04-06T19:24:12Zb2f7a0907f7476a3c1fc1afa8d331bf1f9c3ff62757499842b4753d412c7195e
ACME validationAI security for appsCloudflare OneDDoSLLMLog ExplorerMerkle Tree CertificatesPingoraQUICaccount abuse protectionacknowledgement-based DDoScertificate validationclient-side securitygraph neural networksphishingpost-quantum cryptographyrequest smugglingvulnerability scanner

What happened

Collection of Cloudflare security blog posts (Mar 2026–late 2025) announcing new security products and research, plus several disclosed and fixed vulnerabilities. Key items: Client-Side Security with a cascading AI detection (GNNs + LLMs) now available broadly; AI Security for Apps GA; Account Abuse Protection (Early Access); a new Web & API vulnerability scanner and Log Explorer enhancements; and multiple vulnerability disclosures/fixes — request smuggling in Pingora OSS (fixed in Pingora 0.8.0), a vulnerability in Cloudflare’s ACME certificate validation automation (mitigations described), &

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
b2f7a0907f7476a3c1fc1afa8d331bf1f9c3ff62757499842b4753d412c7195e
Enrichment time
2026-04-06T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.