Cloudflare Client-Side Security: smarter detection, now open to everyone
2026-04-06T19:24:12Z•b2f7a0907f7476a3c1fc1afa8d331bf1f9c3ff62757499842b4753d412c7195e
ACME validationAI security for appsCloudflare OneDDoSLLMLog ExplorerMerkle Tree CertificatesPingoraQUICaccount abuse protectionacknowledgement-based DDoScertificate validationclient-side securitygraph neural networksphishingpost-quantum cryptographyrequest smugglingvulnerability scanner
What happened
Collection of Cloudflare security blog posts (Mar 2026–late 2025) announcing new security products and research, plus several disclosed and fixed vulnerabilities. Key items: Client-Side Security with a cascading AI detection (GNNs + LLMs) now available broadly; AI Security for Apps GA; Account Abuse Protection (Early Access); a new Web & API vulnerability scanner and Log Explorer enhancements; and multiple vulnerability disclosures/fixes — request smuggling in Pingora OSS (fixed in Pingora 0.8.0), a vulnerability in Cloudflare’s ACME certificate validation automation (mitigations described), &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- b2f7a0907f7476a3c1fc1afa8d331bf1f9c3ff62757499842b4753d412c7195e
- Enrichment time
- 2026-04-06T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.