---
title: "Cloudflare attacks its own firewall with AI models and finds gaps"
description: "An automated tester generated 1,107 attack variations; 49 survived review, most in command injection and request forgery"
author: "rews desk"
published: 2026-09-29T13:00:00Z
modified: 2026-09-29T21:06:16Z
url: https://rews.cc/a/cloudflare-attacks-its-own-firewall-with-ai-models-and-finds-4a9480
language: en
tags: ["ai", "cybersecurity", "waf", "openai", "automation", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Cloudflare attacks its own firewall with AI models and finds gaps

*An automated tester generated 1,107 attack variations; 49 survived review, most in command injection and request forgery*

By rews desk · September 29, 2026 · https://rews.cc/a/cloudflare-attacks-its-own-firewall-with-ai-models-and-finds-4a9480

## In brief

- Cloudflare’s AI-driven tester sent 1,107 attack requests at an authorized customer staging site across six attack categories
- 49 unblocked requests survived human review as findings; 48 involved command injection or server-side request forgery
- The models had no access to firewall rules, rule IDs or attack scores during testing
- The work produced three Managed Ruleset changes, including two SSRF detections in the July 21 release
- Cloudflare said software patching remains essential because a firewall bypass still requires an exploitable application

Cloudflare said on Tuesday it used frontier artificial intelligence models to attack its own web application firewall, finding that the system blocked nearly all of 1,107 attempts but let some payloads through.

The company said its automated tester ran 45 scenarios across six attack categories against an authorized customer staging environment, and that human review of requests the firewall did not block left 49 findings worth investigating, 48 of them in command injection and server-side request forgery.

“Is your WAF ready for frontier AI models?” the company wrote on its blog, describing a question it said customers keep asking. Cloudflare said large language models can iterate and mutate attack payloads faster than any human hacker, switching encodings, moving payloads within a request or moving to a different vulnerability in real time.

The tester began with exploits the firewall already blocked, then used two model calls per step: one to propose the next variation and one to review the response and choose what to try next. Cloudflare said the models received no internal information, including rule expressions, rule IDs, WAF Attack Score details or the identity of the security layer that acted, and that code, not the models, sent every request against an allowlisted host.

A request that was not blocked counted as a lead for human review, not a confirmed exploit, the company said. The firewall in the test zone blocked traffic scoring 30 or below on the WAF Attack Score, with the full Cloudflare Managed Ruleset and the OWASP Core Ruleset at Paranoia Level 3 enabled; Cloudflare said the results describe the configured boundary as a whole rather than any single rule.

Overall coverage was near full for cross-site scripting, SQL injection, local file inclusion and Log4j attacks, the company said. Researchers discarded requests that were malformed, benign, duplicate or out of scope, and applied five checks before counting anything as a finding.

In one recorded server-side request forgery session, the tester sent the same cloud metadata address in integer, octal and trailing-dot forms. The firewall blocked all but one: at attempt 18, the trailing-dot form drew a redirect rather than a block, prompting the question of whether a trailing dot changes how the firewall reads a destination. Cloudflare said this was a lead, not proof the metadata was accessed.

The findings were grouped into four sets of candidate rules, which Cloudflare validated and tested against live traffic to assess false-positive risk. The work produced three changes to Cloudflare’s Managed Ruleset: new detections for SSRF - Obfuscated Host and SSRF - Restricted Protocol in the July 21 release, and an improvement to the existing SSRF - Cloud rule. The Obfuscated Host detection came directly from requests that encoded internal addresses in non-standard numeric forms, the company said.

Cloudflare said the exercise is becoming a foundational building block of its firewall development lifecycle.

The company advised customers to deploy their firewall correctly and to patch their software, saying a payload that bypasses the firewall still needs an exploitable application to succeed.
