Independent tech intelligence, checked against primary sources.

TechPulseMind Useful technology.
No manufactured hype.

Cloudflare Ships Beta Fix for Quantum Downgrade Attacks on IPsec

Cloudflare has built an IETF-backed mitigation against quantum downgrade attacks on IPsec and put it in beta across Cloudflare IPsec, WAN and Magic Transit.

Cloudflare Ships Beta Fix for Quantum Downgrade Attacks on IPsec

Cloudflare has implemented a mitigation against downgrade attacks on IPsec and made it available in beta across its IPsec products, the company announced on September 29, 2026. The work was done with the IETF, according to Cloudflare, and covers Cloudflare IPsec, Cloudflare WAN and Magic Transit.

The problem it addresses is a familiar one in the post-quantum migration: as long as devices must still talk to endpoints that only support classical cryptography, an attacker sitting between a client and a server can manipulate the messages they exchange so that each side believes the other does not support post-quantum cryptography at all. The connection then falls back to classical crypto — which a quantum computer could break.

A design flaw that bypasses authentication choice

Cloudflare says it rediscovered a design flaw in IPsec that allows a more sophisticated version of this attack. The company states that the vulnerability lets a quantum attacker decrypt all traffic between post-quantum-capable endpoints, regardless of which authentication method is used.

Pulling it off is not trivial. According to Cloudflare, the attack requires a quantum computation to be carried out in real time during the protocol handshake, unlike a harvest-now, decrypt-later attack where the quantum work happens entirely offline. Cloudflare writes that it does not yet know if and when the attack will be feasible, but points to resource estimates for quantum attacks on public key cryptography that have decreased dramatically as a reason for caution.

The broader context is the migration away from Diffie-Hellman key agreement toward post-quantum mechanisms such as ML-KEM, and from classical signature schemes like ECDSA and RSA toward post-quantum schemes such as ML-DSA. Cloudflare notes that it will take years before all clients and servers on the Internet are upgraded, which is why backwards compatibility — and the downgrade risk that comes with it — remains necessary for now.

Cloudflare has previously made post-quantum encryption the default in its products, open-sourced part of its internal cryptography discovery tool, launched post-quantum visibility features and worked on the web’s move to post-quantum certificates.

Availability

The IPsec downgrade mitigation is in beta across Cloudflare’s IPsec products. Cloudflare has not published pricing or a general-availability date for the feature in the announcement.

Related reading

Sources

Some links on this page may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. See our affiliate disclosure.