I’m the researcher credited for CVE-2026-14440. I’m posting here to ask for help pressure-testing the threat model. Cloudflare Universal SSL is the default free automated certificate system for active Cloudflare zones.…
| CVE ID | CVE-2026-14440 |
| Vendor | reddit_cyber |
| Affected Product | Threat Intelligence |
| Vulnerability Type | Security Vulnerability |
| CVSS Score | 8.0 (HIGH) |
| EPSS Score | 0.1% probability of exploitation in the next 30 days |
| Actively Exploited | ✅ Yes |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via reddit_cyber) |
I’m the researcher credited for CVE-2026-14440. I’m posting here to ask for help pressure-testing the threat model. Cloudflare Universal SSL is the default free automated certificate system for active Cloudflare zones. In the affected configuration, Cloudflare’s authoritative DNS can serve an automatically managed CAA RRset instead of the stricter CAA policy configured by the domain owner, if he/she wants to use them. RFC 8657 lets a domain owner narrow certificate issuance with accounturi and validationmethods - e.g. “this CA may issue, but only from my ACME account / only using this validation method.” If the CA never sees those parameters in the actually served CAA response, that extra control is not enforced at all. What is publicly established at this moment: - NVD describes exploitat
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.