Skip to content

Changelog

New updates and improvements at Cloudflare.

Back to all posts

WAF Release - 2025-09-26

Managed Ruleset Updated

This update introduces 11 new detections in the Cloudflare Managed Ruleset (all currently set to Disabled mode to preserve remediation logic and allow quick activation if needed). The rules cover a broad spectrum of threats - SQL injection techniques, command and code injection, information disclosure of common files, URL anomalies, and cross-site scripting.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset100859ASQLi - UNION - 3N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100889Command Injection - Generic 9N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100890Information Disclosure - Common Files - 2N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100891Anomaly:URL - Relative PathsN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100894XSS - Inline FunctionN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100895XSS - DOMN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100896SQLi - MSSQL Length EnumerationN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100897Generic Rules - Code Injection - 3N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100898SQLi - EvasionN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100899SQLi - Probing 2N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset100900SQLi - ProbingN/ADisabledThis is a New Detection