Cloudflare WAF Faces Adaptive AI Probes
Cloudflare tested its WAF against an adaptive, black-box AI tester across 45 scenarios and 1,107 attempts, finding 49 issues after human review. The results produced new protections, especially for command injection and SSRF.
The important result is not that individual payloads passed, but that adaptive mutation exposed gaps static security tests can miss.
- –XSS, SQLi, LFI, and Log4j coverage was nearly complete.
- –Command injection and SSRF accounted for 48 of 49 findings.
- –A trailing-dot cloud metadata address triggered a redirect instead of a WAF block, creating a lead for investigation—not proof of exploitation.
- –Human triage remains essential because a request passing the WAF is not automatically a vulnerability.
- –Repeating the test with a second model version surfaced similar issues, suggesting the approach is reproducible.
DISCOVERED
1h ago
2026-09-29
PUBLISHED
1h ago
2026-09-29
RELEVANCE
AUTHOR
AIQuanting