PatchSiren

Cloudflare CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Cloudflare CVE published 2026-07-02

CVE-2026-14440

The CVE-2026-14440 vulnerability affects Cloudflare Universal SSL, which adds Certification Authority Authorization (CAA) DNS records that override user-configured CAA records. The Universal SSL CAA records may be more permissive than user-configured records, allowing an attacker with appropriate network access to spoof domain validation and obtain a certificate for the target domain. This vulnerability h [truncated]