Unlocking the Cloudflare app ecosystem with OAuth for all
2026-06-30T19:24:08Z•bf8adf0406f5821ed7649238a71dccd7edd0f1e5615f12c9ac0c35178a90bf3e
Account Abuse ProtectionAutomated TriageClient-Side SecurityCloudforce OneCopy FailHybrid ML-KEMIPsecLLM SecurityLinux kernelManaged OAuthMythosOAuthPQCPingoraPost-QuantumPrivilege EscalationProject GlasswingRFC 9728Request SmugglingSelf-Managed OAuthThreat IntelligenceVulnerability DiscoveryVulnerability HarnessWAFWeb & API Vulnerability Scanner
What happened
Collection of Cloudflare blog posts (Mar–Jun 2026) covering security product launches, vulnerability disclosures and mitigations, and research into AI/LLM threats. Key items include broad availability of Self‑Managed and Managed OAuth (zero‑downtime migration and RFC 9728 adoption), post‑quantum roadmaps and GA post‑quantum IPsec (hybrid ML‑KEM), disclosures and mitigations for a critical Linux kernel privilege escalation (“Copy Fail”) and request‑smuggling bugs in Pingora OSS (fixed in Pingora 0.8.0), advances in WAF automation via Cloudforce One threat intel (cf.intel), new Web & API Vulner
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- bf8adf0406f5821ed7649238a71dccd7edd0f1e5615f12c9ac0c35178a90bf3e
- Enrichment time
- 2026-06-30T19:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.