Introducing Cloudflare’s Web and API Vulnerability Scanner (Open Beta)
Cloudflare is launching the Open Beta of the Web and API Vulnerability Scanner for all API Shield customers. This new, stateful Dynamic Application Security Testing (DAST) platform helps teams proactively find logic flaws in their APIs.
The initial release focuses on detecting Broken Object Level Authorization (BOLA) vulnerabilities by building API call graphs to simulate attacker and owner contexts, then testing these contexts by sending real HTTP requests to your APIs.
The scanner is now available via the Cloudflare API. To scan, set up your target environment, owner and attacker credentials, and upload your OpenAPI file with response schemas. The scanner will be available in the Cloudflare dashboard in a future release.
Access: This feature is only available to API Shield subscribers via the Cloudflare API. We hope you will use the API for programmatic integration into your CI/CD pipelines and security dashboards.
Documentation: Refer to the developer documentation to start scanning your endpoints today.
Source: Cloudflare
Latest Posts
- Find your files quickly and easily on Word, Excel and PowerPoint App home pages [MC1249435]
![Find your files quickly and easily on Word, Excel and PowerPoint App home pages [MC1249435] 2 pexels e l 296481171 14209547](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Retirement of the Semi-Annual Enterprise Channel option in the Office Deployment Service [MC1249427]
![Retirement of the Semi-Annual Enterprise Channel option in the Office Deployment Service [MC1249427] 3 pexels jeshoots 234527](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Purview compliance portal: Data Security Investigations introduces new soft purge mitigation action [MC1249429]
![Microsoft Purview compliance portal: Data Security Investigations introduces new soft purge mitigation action [MC1249429] 4 pexels kinkate 368260](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Teams: Live transcription in Teams Rooms on Android [MC1249432]
![Microsoft Teams: Live transcription in Teams Rooms on Android [MC1249432] 5 pexels magda ehlers pexels 613431](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Find your files quickly and easily on Word, Excel and PowerPoint App home pages [MC1249435] 2 pexels e l 296481171 14209547](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-e-l-296481171-14209547-150x150.webp)
![Retirement of the Semi-Annual Enterprise Channel option in the Office Deployment Service [MC1249427] 3 pexels jeshoots 234527](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-jeshoots-234527-150x150.webp)
![Microsoft Purview compliance portal: Data Security Investigations introduces new soft purge mitigation action [MC1249429] 4 pexels kinkate 368260](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-kinkate-368260-150x150.webp)
![Microsoft Teams: Live transcription in Teams Rooms on Android [MC1249432] 5 pexels magda ehlers pexels 613431](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-magda-ehlers-pexels-613431-150x150.webp)
