Cloudflare rolls out context-aware vulnerability triage that links code flaws to live traffic and edge protections
Cloudflare has introduced early access to a new invitation-only service called Vulnerability Discovery and Remediation, positioning it as an answer to a problem security teams have been struggling with for years: vulnerability scanning increasingly produces mountains of findings, but prioritization still depends on whether the vulnerable code is actually reachable, actively targeted, and adequately protected in production.
Under the umbrella of Cloudflare Managed Defense, the service combines automated vulnerability analysis with production-aware evidence from Cloudflare’s network—active routes, traffic volume, and Web Application Firewall (WAF) controls—so that fixes are ranked by likely real-world exposure rather than by scanner output alone. For customers, the workflow is designed to be human-in-the-loop: Cloudflare can propose code patches and edge mitigations, but customers decide what gets applied.
The approach also reflects a shift in how infrastructure providers are operationalizing AI for security: not as