HomeCVE Intelligence › CVE-2026-14440
CVSS 8.0 HIGH 🔴 ACTIVELY EXPLOITED Security Vulnerability

CVE-2026-14440: Cloudflare’s CAA flaw looks impractical for criminals

I’m the researcher credited for CVE-2026-14440. I’m posting here to ask for help pressure-testing the threat model. Cloudflare Universal SSL is the default free automated certificate system for active Cloudflare zones.…

8.0CVSS Score
HIGHSeverity
NOCISA KEV
0.1%EPSS Score
Security VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-14440
Vendorreddit_cyber
Affected ProductThreat Intelligence
Vulnerability TypeSecurity Vulnerability
CVSS Score8.0 (HIGH)
EPSS Score0.1% probability of exploitation in the next 30 days
Actively Exploited✅ Yes
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via reddit_cyber)

🔬 Technical Analysis

I’m the researcher credited for CVE-2026-14440. I’m posting here to ask for help pressure-testing the threat model. Cloudflare Universal SSL is the default free automated certificate system for active Cloudflare zones. In the affected configuration, Cloudflare’s authoritative DNS can serve an automatically managed CAA RRset instead of the stricter CAA policy configured by the domain owner, if he/she wants to use them. RFC 8657 lets a domain owner narrow certificate issuance with accounturi and validationmethods - e.g. “this CA may issue, but only from my ACME account / only using this validation method.” If the CA never sees those parameters in the actually served CAA response, that extra control is not enforced at all. What is publicly established at this moment: - NVD describes exploitat

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-14440 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence