Cloudflare vulnerabilities
2 CVEs tracked
Cloudflare appears in our recent reports primarily in the context of internet disruptions, security integrations, and threat intelligence. Key themes include brand impersonation as an initial access vector, the release of Attribution Business Insights, and the integration of Cloudforce One threat intel into real-time WAF rules. Specific CVEs highlighted in the reports are `CVE-2026-11325`, concerning an RCE in an archived repository, and `CVE-2026-15239`, a critical CAPTCHA bypass in a WordPress plugin. Defenders should audit GitHub Actions configurations and patch the vulnerable WordPress plugin without delay.
Azərbaycanca: Cloudflare, son hesabatlarımızda internet kəsintiləri, təhlükəsizlik inteqrasiyaları və təhlükə kəşfiyyatı kontekstində tez-tez görünür. Şirkət brend imitasiyası (Cloudflare adından saxta səhifələr) kimi ilkin giriş vektorları ilə bağlı xəbərdarlıq edib və real-vaxt WAF qaydaları üçün Cloudforce One kəşfiyyatını təqdim edib. Hesabatlarda `CVE-2026-11325` (arxivləşmiş repoda RCE) və `CVE-2026-15239` (Turnstile bypassı) xüsusi olaraq vurğulanır; müdafiəçilər GitHub Actions konfiqurasiyalarını yoxlamalı və sözügedən WordPress plaginini yeniləməyə diqqət yetirməlidir.
This vendor's CVEs2
This hub is built from skopnix's own reporting on Cloudflare: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.