MEDIUM
Cloudflare
CVE published 2026-07-02
CVE-2026-14440
The CVE-2026-14440 vulnerability affects Cloudflare Universal SSL, which adds Certification Authority Authorization (CAA) DNS records that override user-configured CAA records. The Universal SSL CAA records may be more permissive than user-configured records, allowing an attacker with appropriate network access to spoof domain validation and obtain a certificate for the target domain. This vulnerability h [truncated]