
Cloudflare is bringing OpenAI’s cybersecurity models into its vulnerability management workflow, allowing selected customers to investigate software vulnerabilities, use production data to assess their exposure and propose security measures while engineers review permanent fixes.
The company announced Vulnerability Discovery and Remediation on September 3, 2026. The invitation-only service is being offered through Cloudflare Managed Defense and uses models from OpenAI’s Daybreak Defense Network, including GPT-5.6 Cyber.
The service connects findings from authorized source code with information about an application’s production routes, traffic and security activity. Cloudflare says this context can help security teams determine which findings warrant greater attention.
Cloudflare said the National Vulnerability Database had recorded 60,475 vulnerabilities by September 2026, compared with 48,185 during all of 2025.
The company said the increasing number of vulnerabilities makes it harder for security teams to determine which findings are relevant to their production environments and should be addressed first.
Cloudflare’s service uses information from its Web Assets and Web Application Firewall systems to obtain information about active routes, traffic and security events.
For Cloudflare Workers, the process can retrieve the latest source version and configured routes and connect those routes with information from Workers Observability.
A reconnaissance stage maps request paths to portions of the authorized codebase. Hunter agents are then used to examine relevant sections of the code for potential vulnerabilities.
Cloudflare said network activity is used as supporting context rather than as proof that a vulnerability exists. Findings must be supported by evidence in the source code.
The findings then go through validation. Cloudflare said the initial assessment is based on evidence from the source code, while production information can affect the priority assigned to a finding.
For example, information about traffic to an affected route or security activity involving that route can provide additional context when Cloudflare assesses the finding.
The workflow can produce a proposed code patch for engineering review and, where appropriate, a proposed WAF rule intended to reduce exposure while the underlying code is being fixed.
Cloudflare said its example of the process involves an HTTP method override bypass. The system connects the source-code finding with a production route and uses available traffic and security information when determining an appropriate edge mitigation.
The proposed WAF protection is intended to be scoped around the request characteristics associated with the vulnerable code. Cloudflare said the system does not recommend a rule when a route pattern consists only of variables and wildcards because the available evidence is insufficient to establish a specific connection.
The service does not mean that OpenAI’s models run directly on Cloudflare’s network edge.
According to Cloudflare, the investigation harness runs on Cloudflare, while model requests are sent through Cloudflare AI Gateway to OpenAI’s servers. The responses are then returned to the Cloudflare-based workflow.
Cloudflare said no model inference runs at its edge and that the model cannot deploy a rule or patch itself.
The company has also described controls governing access to customer information. Investigations are limited to material that the customer authorizes Cloudflare to access, and Cloudflare said unnecessary context is removed before information is sent to the model.
Cloudflare also applies configured redaction controls. Source code, logs and request metadata are treated as evidence for the investigation rather than instructions to the model.
Tool calls are logged and checked against the investigation’s access policy.
Proposed patches and edge rules must pass checks implemented outside the model. Cloudflare said the workflow stops if those checks fail.
For proposed WAF rules, Cloudflare validates the rule and tests it against synthetic fixtures representing expected requests rather than directly against customer traffic.
No code fix or edge rule takes effect without customer approval. Customers review the proposed remediation and decide whether to test or deploy it.
The new service builds on Cloudflare’s earlier work on AI-assisted vulnerability research. In its vulnerability harness research, Cloudflare described a system for finding potential vulnerabilities, validating findings and producing fixes for review.
Cloudflare has also published research on testing frontier cybersecurity models against its own repositories. The company said those experiments were part of its work to understand the use of increasingly capable AI systems in cybersecurity.
OpenAI’s Daybreak program provides a broader framework for its cybersecurity partnerships. The Daybreak Defense Network brings OpenAI’s cybersecurity models and tools into products and services operated by participating security companies.
OpenAI describes the Daybreak defensive workflow as covering inventory, vulnerability discovery, dynamic validation, ownership assignment and verified remediation.
OpenAI lists Cloudflare alongside other security companies participating in the network, including Akamai, Cato Networks, Check Point, Cisco, CrowdStrike, Darktrace, Elastic, Fortinet, IBM, Okta, Palo Alto Networks, Proofpoint, Red Hat, Trend Micro, SentinelOne, SpecterOps, Sophos, Tenable and Zscaler.
The partnership forms part of OpenAI’s wider cybersecurity initiative. On September 3, 2026, OpenAI announced Daybreak for Frontline Defenders, including a commitment of $1 billion in subsidized access, training, technical support and partnerships for frontline defenders.
For Cloudflare, the current service is limited to selected customers. Vulnerability Discovery and Remediation is available through Managed Defense on an invitation-only early-access basis.
Each engagement begins with a single application whose codebase the customer authorizes Cloudflare to investigate.
Cloudflare has not announced general availability or public pricing for the service.
The service therefore does not represent fully autonomous vulnerability remediation. It combines an AI-assisted investigation workflow with Cloudflare’s existing production and security data, while proposed code changes and edge protections remain subject to validation and customer review.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

