CVE-2026-14440General

LOWCVSS 7.6 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This auto-managed RRset is permissive by design (e.g. 'issue "letsencrypt.org"' without parameters). On Universal SSL zones, Cloudflare's authoritative DNS serves this auto-managed RRset at query time, superseding any customer-configured CAA records on the zone. When a customer publishes a stricter CAA record using the RFC 8657 accounturi or validationmethods parameters, the Certificate Authority does not observe those parameters when evaluating the served RRset under RFC 8659. As a result, the RFC 8657 account-binding and validation-method-binding protections are not enforced end-to-end on Universal SSL zones. Successful exploitation could result in issuance of a browser-trusted TLS certificate to an attacker, enabling MITM against the affected domain. Exploitation is non-trivial in practice: an attacker would need to hold an ACME account at one of the Certificate Authorities in the served CAA RRset and to simultaneously satisfy domain control validation across the multiple geographically distinct Network Perspectives the CA relies on for Multi-Perspective Issuance Corroboration. Cloudflare prefixes are anycast-announced from hundreds of locations globally, raising the bar against single-vantage-point BGP hijacks. Any resulting misissuance of a browser-trusted certificate is subject to Certificate Transparency logging required by major browsers, and would be visible to CT monitoring. Mitigation:  Customers requiring strict RFC 8657 enforcement need to disable Universal SSL on the affected zone. Universal SSL's automatic CAA management and customer-set RFC 8657 accounturi and validationmethods enforcement are mutually exclusive by the nature of the issue, so there is no in-product workaround that preserves both.  Certificate Transparency monitoring is recommended for all customers as a general detection control. Credits: David Osipov (ORCID: https://orcid.org/0009-0005-2713-9242), independent researcher

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-02); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-02: 3Mentions · 2026-07-21: 1Active Exploitation · 2026-07-21: 1Technical Details · 2026-07-02: 107-0207-21
Signal classification2 categories
General
375.0%
Active Exploitation
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-023
General3
2026-07-211
Active Exploitation1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-14440 Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's… https://www.cve.org/CVERecord?id=CVE-2026-14440

    Post summary

    The snippet simply links to the CVE record for CVE-2026-14440, with no additional technical details or actionable information.

    10010700
    57.7K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Cloudflare Universal SSL (CVE-2026-14440) https://vuldb.com/vuln/375783/cti

    Post summary

    The post alerts on detected activity against Cloudflare Universal SSL CVE-2026-14440, indicating it is likely being actively exploited, but no PoC, exploit code, patch, or detailed technical information is supplied.

    00010105
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-14440 Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's… https://www.cve.org/CVERecord?id=CVE-2026-14440 ----- Traducción: CVE-2026-14440 Descri… http://infoflow.cloud`

    Post summary

    A brief reference to CVE-2026-14440 and a link to its record, describing Cloudflare’s Universal SSL updating CAA RRsets, without additional technical or exploitation details.

    0001035
    91 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-14440 Cloudflare Universal SSL CAA Record Bypass Enables TLS Certificate Misis... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14440 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A brief notification of CVE‑2026‑14440, mentioning a Cloudflare Universal SSL CAA record bypass vulnerability, but lacking detailed technical, exploit, patch, or activity information.

    00010129
    4.1K followersView on X

Explore more