This depends on the VPN provider. Private VPN services share IPs between customers, and the extra layer of privacy they provide comes with high potential for abuse. Some providers care more about preventing fraud than others. Cloudfront is likely just blocking IPs that have behaved poorly in the past, so I'd suggest you look for more reputable VPN providers that actively weed out fraudulent users.
Cloudfront customers hate the users who use automated tools to perform click fraud, post fake comments and reviews, send spam, attempt vulnerability scanning, and try to brute-force logins. These malicious users overwhelmingly use VPNs, Tor, and botnets to perform these actions; few use their own connections. Legitimate users overwhelmingly do not use VPNs or Tor. Do you see what's about to happen?
Cloudflare customers want their CDN to block these malicious actors, and Cloudflare can easily identify Tor and VPN providers. Cloudflare adds a captcha, which is intensely annoying to legitimate users, but debilitating to automated users. The vast majority of users are unaffected, and customers are happy, but the few legitimate people using Tor and VPNs conclude that Cloudflare hates them.