# Cloudflare tests its WAF against advanced AI models

> A custom AI‑driven tester sent 1,107 attack attempts to a customer staging site; most were blocked, leading to three new rule updates.

Oossa · 2026-09-29 · https://oossa.com/en/cloudflare-tests-its-waf-against-advanced-ai-models

Cloudflare built a tester that lets a large language model (LLM – the type of AI behind ChatGPT) act like a hacker and try to bypass its web‑application firewall (WAF). The system ran 45 scenarios covering XSS, SQLi, CMDi, SSRF, LFI and Log4j against a staging environment and generated 1,107 request attempts. After human review, 49 attempts were deemed real findings, 48 of them for command injection or SSRF, and the work resulted in three new managed‑ruleset detections released on July 21.

## The facts

- 1,107 total attack attempts across 45 scenarios
- 49 findings after review, leading to three rule updates on July 21

## Why it matters

The test shows AI can quickly expose WAF gaps, helping Cloudflare improve protection for all customers.

## Sources & references

1. [We tested our own WAF with frontier AI models. Here’s what we found](https://blog.cloudflare.com/adaptive-ai-waf-testing/) – Cloudflare, 2026-09-29

Last updated: 2026-09-29
