Cloudflare Partners with OpenAI Daybreak Models to Launch AI-Powered Edge Vulnerability Management

Cloudflare

Cloudflare, has unveiled Vulnerability Discovery and Remediation, which will become available through the Cloudflare Managed Defense program. The Vulnerability Discovery and Remediation technology will utilize the OpenAI Daybreak Defense Network to deliver solutions that will combine code-level analysis and automatic patching by leveraging the power of OpenAI Daybreak model, including GPT-5.6 Cyber, along with security context and traffic insights from the Cloudflare global infrastructure.

Overcoming the Vulnerability Backlog at Enterprise Scale

The speed at which software bugs are reported has hit unprecedented heights, making legacy security management solutions useless. The NVD had already identified 60,475 software vulnerabilities by September 2026. In the entire year of 2025, there were only 48,185 security vulnerabilities discovered.

Legacy vulnerability scanners raise thousands of alerts each day. But, most of these alerts don’t have any information about the current operations, leaving no way to separate the noise from the active threats. Consequently, cybersecurity teams have started taking a lot of time to manage the noise, leaving behind the actual threats.

Also Read: PwC US and Palantir Expand Partnership to Accelerate Enterprise AI Scaling and Modernization

Cloudflare manages trillions of requests every day over millions of web properties around the world. Unlike legacy point solutions that use network logs and code scans to detect potential threats, Cloudflare uses its huge network power to detect and manage operational anomalies. This threat intelligence gives cybersecurity teams the chance to fix structural issues and zero-day exploits even before they reach other users.

“If your security team is manually fighting AI-driven attacks, you’re not just burning them out-you’re losing. Now, we’re shifting the defense strategy away from chasing patches one vulnerability at a time to an automated approach,” said Matthew Prince, co-founder and CEO of Cloudflare. “We built Cloudflare’s global network to analyze what’s happening across the Internet in real time. Pair that with the power of OpenAI GPT-5.6 Cyber, and you’re not just reacting to attacks anymore, you’re stopping them before they land.”

“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, Head of Global Cyber Partnerships at OpenAI. “We are excited to team up with Cloudflare to put proactive, AI-driven security directly into the hands of enterprise defenders.”

Unified Platform Capabilities and Governance Guardrails

By embedding AI-driven code analysis directly into its platform-unifying Web Assets, Web Application Firewall (WAF), and Workers Observability-Cloudflare moves enterprises beyond static vulnerability reporting to context-driven threat prioritization and automated defense.

Eligible early-access customers receive three primary operational capabilities:

Threat Triaging Through Contextual Correlation: Integrates live traffic data correlation with static code analysis, enabling security professionals to prioritize threats being actively exploited, while other, less critical vulnerabilities remain proportionate.

Immediate Edge Defense: Provides administrators with the ability to deploy on-the-fly WAF mitigation policies designed specifically to counteract attack vectors, thus safeguarding the network edge prior to any software fix development.

Automated Code Patch Writing: Utilizes OpenAI Daybreak machine learning models, such as GPT-5.6 Cyber, to automatically generate tested code patches for engineering to review, greatly decreasing developer time and effort.

For full control and assurance that no unintended changes will be made to the system, Cloudflare implements a strict “human-in-the-loop” approach: neither automated code patches nor custom WAF policies are implemented without human approval.