Cloudflare is teaming up with OpenAI to use artificial intelligence for something more useful than generating another chatbot. The companies are combining OpenAI’s GPT-5.6 Cyber with Cloudflare’s Internet security network to find software vulnerabilities, identify which ones attackers are actually targeting, and help stop those attacks before developers finish fixing the underlying code.
The new service is called Cloudflare Vulnerability Discovery and Remediation. It is available in early access through Cloudflare Managed Defense and is part of the OpenAI Daybreak Defense Network.
Traditional vulnerability scanners can leave companies with huge lists of possible problems without making it obvious which ones require immediate attention. Cloudflare believes its visibility into live Internet traffic can help narrow that list by showing which vulnerabilities are actually being exploited.
Cloudflare says its network processes trillions of requests every day across millions of web properties. By combining that traffic data with code analysis from OpenAI Daybreak models, including GPT-5.6 Cyber, the company says it can help security teams focus on the vulnerabilities that pose the most immediate risk.
If Cloudflare detects attacks targeting a particular weakness, a customer can have it generate a custom Web Application Firewall rule designed around that attack vector. That could give developers some breathing room by blocking exploitation at the edge while they work on a permanent fix.
OpenAI’s models can also generate a proposed code patch for developers to inspect. Cloudflare says neither the patch nor the edge security rule is deployed automatically. A human must approve both.
That is probably the right approach. Automatically generated security fixes sound convenient until an AI produces a patch that breaks something important in production. AI can shorten the process, but developers and security teams still need to understand what they are approving.
The scale of the vulnerability problem helps explain the push toward more automation. Cloudflare says the National Vulnerability Database had recorded 60,475 vulnerabilities by September 2026, already exceeding the 48,185 recorded during all of 2025.
Cloudflare CEO Matthew Prince argues that security teams cannot keep manually responding as attackers increasingly use AI themselves.
“If your security team is manually fighting AI-driven attacks, you’re not just burning them out—you’re losing. Now, we’re shifting the defense strategy away from chasing patches one vulnerability at a time to an automated approach,” Prince said.
The interesting part of this announcement is not simply that Cloudflare is using AI. Practically every cybersecurity company is doing that now. The bigger idea is connecting AI-generated code analysis with real-world attack activity.
A scanner might tell a company it has hundreds of vulnerabilities. Cloudflare’s approach is meant to help identify which of those vulnerabilities attackers are trying to exploit right now.
There are still reasons for caution. AI-generated code fixes need careful review, and an automatically generated WAF rule does not eliminate the need to repair vulnerable software. Customers are also placing considerable trust in Cloudflare and OpenAI to correctly analyze sensitive code and security data.
Still, the workflow makes sense: find the vulnerability, determine whether attackers are exploiting it, block the attack, and help developers produce a permanent fix.
Cloudflare Vulnerability Discovery and Remediation is currently available by invitation to select Cloudflare Enterprise customers, so this is not something every customer can enable today. If it works as advertised, however, it could make vulnerability management considerably more useful than sorting through another endless list of security warnings.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz