Skip to content

Changelog

New updates and improvements at Cloudflare.

WAF Release - 2026-08-11

This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections.

Key Findings

  • A new detection provides protection against vBulletin CVE-2026-61511.
  • Two existing detections have been improved to strengthen coverage.

Impact

Successful exploitation of CVE-2026-61511 may lead to remote code execution on affected vBulletin systems, potentially resulting in unauthorized access, data exposure, service disruption, and broader compromise of the hosting environment. Administrators are strongly encouraged to apply vendor updates and recommended mitigations.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AvBulletin - Remote Code Execution - CVE:CVE-2026-61511LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AVersion Control - Information Disclosure - BetaLogBlockThis rule is merged into the original rule "Version Control - Information Disclosure" (ID: )
Cloudflare Managed RulesetN/AvBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132 - BetaLogBlockThis rule is merged into the original rule "vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132" (ID: )

WAF Release - 2026-08-07

This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule.

Key Findings

  • CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen. Exploitation requires social engineering and explicit interaction by the target user. Under additional conditions, it may be escalated to remote code execution.

Impact

The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AWordpress - XSS - CVE:CVE-2026-64638BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Free RulesetN/AWordpress - XSS - CVE:CVE-2026-64638BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Managed RulesetN/ACommand Injection - ObfuscationBlockDisabledDetection logic has been deprecated

WAF Release - 2026-08-04

This release introduces new rules and updates Microsoft SharePoint RCE alongside enhanced SSRF cloud protection rule actions.

Key Findings

  • CVE-2026-50522: An insecure deserialization vulnerability in Microsoft SharePoint Server. This may allow an unauthenticated attacker to execute arbitrary code using crafted requests.
  • CVE-2026-66066: An improper input processing vulnerability in Ruby on Rails Active Storage image variant transformations. This may allow an unauthenticated attacker to perform arbitrary file reads and achieve Remote Code Execution (RCE) using maliciously crafted payload requests.
  • Generic Cloud Protections: Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AMicrosoft SharePoint - Remote Code Execution - CVE:CVE-2026-50522LogBlock

This is a new detection.

Cloudflare Managed RulesetN/ARails - Arbitrary File Read & RCE - CVE:CVE-2026-66066BlockBlock

This was labeled as File Upload - RCE.

Cloudflare Managed RulesetN/ASSRF - LocalDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/ASSRF - Local - 2 - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/ASSRF - Cloud - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/ASSRF - Cloud - 2 - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/ASSRF - CloudDisabledBlock

We are changing the action for this rule from Disabled to BLOCK

Cloudflare Managed RulesetN/ASSRF - Local - BetaDisabled -

This detection has been removed.

WAF Release - 2026-07-29

This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Nuxt Server Island components and Alibaba Fastjson deserialization routines, alongside enhanced protections for cloud metadata Server-Side Request Forgery (SSRF) and obfuscated command injection attempts.

Key Findings

  • Nuxt Server Island - RCE(GHSA-9473-5f9j-94wq): An unauthenticated vulnerability in Nuxt Server Islands where remote attackers can supply arbitrary component names or props to endpoints. Manipulating these parameters allows unauthenticated component Remote Code Execution (RCE) on the server.

  • Alibaba Fastjson JSONType Remote Code Execution: A unauthenticated remote code execution vulnerability in Alibaba Fastjson (≤ 1.2.83) during JSON deserialization. Under default configurations, attackers can execute arbitrary system commands, bypassing traditional classpath and gadget-based defenses.

  • Generic Protections (SSRF & Command Injection): Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications, alongside new rules targeting obfuscated command injection patterns across request parameters.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASSRF - Cloud - BetaLogBlock

This is an improved detection.

Cloudflare Managed RulesetN/ACommand Injection - ObfuscationLogBlock

This is a new detection.

Cloudflare Managed RulesetN/AAlibaba Fastjson JSONType Remote Code Execution - BodyLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ANuxt Server Island - RCEN/ABlock

This is a new detection.This was labeled as Generic Rules - RCE.

Cloudflare Managed RulesetN/AGeneric Rules - RCEN/ABlock

This is a new detection.

Cloudflare Managed RulesetN/AGeneric Rules - XSSN/ABlock

This is a new detection.

Cloudflare Managed RulesetN/AFile Upload - RCEN/ABlock

This is a new detection.

Cloudflare Free RulesetN/AGeneric Rules - RCEN/ABlock

This is a new detection.

Cloudflare Free RulesetN/AGeneric Rules - XSSN/ABlock

This is a new detection.

Cloudflare Free RulesetN/AFile Upload - RCEN/ABlock

This is a new detection.

WAF Release - 2026-07-21

This release introduces new rules for vulnerabilities in Adobe ColdFusion, Next.js, WordPress alongside updates to existing rules thereby providing enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS).

WAF and framework adapter mitigations for Next.js vulnerabilities

Multiple security vulnerabilities were disclosed and patched by the Next.js team through July 2026 security release. These include denial of service, middleware and proxy bypass, server-side request forgery, information disclosure, and cache poisoning across a range of severities.

Several of the disclosed vulnerabilities are not possible to block at WAF layer,we strongly recommend updating your application and its dependencies immediately. Patched versions are available through v16.2.11 (Active LTS) and v15.5.21 (Maintenance LTS) to address these issues.

AdvisoryCVESeverityIssueWAF Coverage
Denial of Service in App Router using Server ActionsCVE-2026-64641High

Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage. The CPU usage blocks processing of further requests in the same process, leading to Denial of Service.

WAF rule Next.js - DoS - CVE-2026-64641 () has been deployed to provide coverage.

Middleware / Proxy bypass in App Router applications using Turbopack and single localeCVE-2026-64642High

Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales are vulnerable to a middleware/proxy bypass. Accordingly, any authentication or security checks that a middleware/proxy may perform are bypassed.

This is a middleware bypass that unfortunately cannot be covered through Cloudflare WAF signature engine.

Server-Side Request Forgery in rewrites via attacker-controlled destination hostnameCVE-2026-64645High

A rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For rewrites, this behavior enables Server-Side Request Forgery (SSRF); for redirects, Open Redirect can be achieved.

Existing SSRF rules provide adequate coverage for this vulnerability, no tailored WAF rule was developed.

Server-Side Request Forgery in Server Actions on custom serversCVE-2026-64649High

When a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker’s request to control Host-associated headers.

WAF rule Next.js - SSRF - CVE-2026-64649 () has been deployed to provide coverage.

Denial of Service in the Image Optimization API using SVGsCVE-2026-64644Medium

When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, the images can cause CPU exhaustion in the /_next/image endpoint.

Malicious request is unfortunately indistinguishable from a legitimate image optimization request, so no WAF rule has been created to address this vulnerability.

Unbounded Server Action payload in Edge runtimeCVE-2026-64646Medium

A crafted request can lead to memory consumption on Server Actions in the Edge runtime. Next.js applications which use App Router and have at least one Server Action are affected.

Unfortunately there is no one size fits all rule that can be deployed through WAF in lieu of custom bodySizeLimit configurations, so no WAF rule has been created to address this vulnerability.

Unauthenticated disclosure of internal Server Function endpointsCVE-2026-64643Medium

In Next.js applications using App Router, Server Actions (use server) or use cache endpoint IDs can be globally disclosed. An attacker can use this for reconnaissance and as part of a broader attack chain.

WAF rule Next.js - Information Disclosure - CVE-2026-64643 () has been deployed to provide coverage.

Cache confusion of response bodies for requests with bodiesCVE-2026-64648Medium

A server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. This only applies for fetch calls of the shape fetch(new Request(init), aDifferentInit)

This is an application logic bug that unfortunately cannot be covered through Cloudflare WAF signature engine.

Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequencesCVE-2026-64647Medium

A server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. This only applies when receiving request bodies which contain invalid UTF-8 characters.

This is an application logic bug that unfortunately cannot be covered through Cloudflare WAF signature engine.

Key Findings

  • CVE-2026-48276: A path traversal vulnerability in Adobe ColdFusion file upload mechanisms allows unauthenticated attackers to write or upload files to arbitrary locations outside designated directories on the origin server.

  • CVE-2026-48282: A path traversal vulnerability in Adobe ColdFusion enables unauthenticated attackers to manipulate directory sequences and access restricted system files on the host filesystem.

  • CVE-2026-60137: An unauthenticated SQL injection vulnerability affecting WordPress. Threat actors exploit unsanitized input parameters to execute arbitrary SQL queries, leading to unauthorized database access, record manipulation, or data exfiltration.

  • CVE-2026-63030: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASSRF - Restricted ProtocolLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASSRF - Obfuscated HostLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ALFI - Path TraversalLogBlock

This is a new detection.

Cloudflare Managed RulesetN/AAdobe ColdFusion - File Upload Path Traversal - CVE:CVE-2026-48276LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AAdobe ColdFusion - Path Traversal - CVE:CVE-2026-48282LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AXSS — JS Bracket Concat Obfuscation - BodyLogDisabled

This is a new detection.

Cloudflare Managed RulesetN/AXSS — JS Bracket Concat Obfuscation - HeadersLogDisabled

This is a new detection.

Cloudflare Managed RulesetN/AXSS — JS Bracket Concat Obfuscation - URILogBlock

This is a new detection.

Cloudflare Managed RulesetN/AWordpress - SQL Injection - CVE:CVE-2026-60137N/ABlock

This was labeled as Generic Rules - SQLi.

Cloudflare Managed RulesetN/AWordpress - Remote Code Execution - CVE:CVE-2026-63030N/ABlock

This was labeled as Generic Rules - Unauthenticated RCE.

Cloudflare Free RulesetN/AWordpress - SQL Injection - CVE:CVE-2026-60137N/ABlock

This was labeled as Generic Rules - SQLi.

Cloudflare Free RulesetN/AWordpress - Remote Code Execution - CVE:CVE-2026-63030N/ABlock

This was labeled as Generic Rules - Unauthenticated RCE.

Cloudflare Managed RulesetN/ANext.js - Information Disclosure - CVE-2026-64643N/ABlock

This was labeled as Generic Rules - Information Disclosure.

Cloudflare Managed RulesetN/ANext.js - SSRF - CVE-2026-64649N/ABlock

This was labeled as Generic Rules - Auth Bypass - 2.

Cloudflare Managed RulesetN/ANext.js - Remote Code Execution - Cache ComponentsN/ABlock

This was labeled as Generic Rules - RCE.

Cloudflare Managed RulesetN/ANext.js - DoS - CVE-2026-64641N/ABlock

This was labeled as Generic Rules - DoS.

Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - Body - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - Header - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - URI - BetaDisabled -

This detection has been removed.

WAF Release - 2026-07-17 - Emergency

This emergency release adds a new managed rule to block active exploitation of a critical remote code execution (RCE) and SQL injection (SQLi) vulnerability found in popular web frameworks.

Key Findings

  • Generic Frameworks - Unauthenticated RCE: Attackers can execute arbitrary system commands with web server privileges by sending malicious input containing invalid path sequences during request processing.

  • Generic Frameworks - SQLi: Attackers can execute unauthorized database queries due to a failure to sanitize input values within request parameters.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AGeneric Rules - Unauthenticated RCEN/ABlockThis is a new detection.
Cloudflare Managed RulesetN/AGeneric Rules - SQLi N/ABlockThis is a new detection.
Cloudflare Free RulesetN/AGeneric Rules - Unauthenticated RCE N/ABlockThis is a new detection.
Cloudflare Free RulesetN/AGeneric Rules - SQLi N/ABlockThis is a new detection.

WAF Release - 2026-07-14

This release introduces new rules targeting critical infrastructure vulnerabilities. These include an unauthenticated memory disclosure flaw in Citrix NetScaler ADC and Gateway (CVE-2026-8451) and a high-severity pre-authentication remote code execution (RCE) vulnerability in Progress Kemp LoadMaster (CVE-2026-8037).

Key Findings

  • CVE-2026-8451: An insufficient input validation vulnerability affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML Identity Provider (IdP). Remote, unauthenticated attackers can exploit this flaw by sending malformed requests to trigger a memory overread, allowing them to leak chunks of sensitive data from adjacent appliance memory.

  • CVE-2026-8037: A critical OS command injection vulnerability in Progress Kemp LoadMaster load balancers allows unauthenticated remote attackers to achieve remote code execution (RCE).

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ACitrix Netscaler ADC - Insufficient Input Validation - CVE:CVE-2026-8451LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AProgress Kemp LoadMaster - Remote Code Execution - CVE:CVE-2026-8037LogBlock

This is a new detection.

WAF Release - 2026-07-01

This release adds targeted coverage for a path traversal flaw in Fortinet FortiSandbox (CVE-2026-39813) and transitions the Anomaly:Header:User-Agent - Fake Bing or MSN Bot rule action from Block to Disabled.

Key Findings

  • CVE-2026-39813: A path traversal vulnerability in Fortinet FortiSandbox allows remote, unauthenticated attackers to read arbitrary files from the underlying filesystem due to insufficient validation of user-supplied input paths.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AFortinet FortiSandbox - Path Traversal - CVE:CVE-2026-39813LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AAnomaly:Header:User-Agent - Fake Bing or MSN BotEnabledDisabled

We are changing the action for this rule from BLOCK to Disabled

WAF Release - 2026-06-23

This week's release introduces new managed protection to address a critical pre-authentication OS command injection vulnerability in Ivanti Sentry (CVE-2026-10520).

Key Findings

  • CVE-2026-10520: An OS command injection vulnerability in Ivanti Sentry allows remote, unauthenticated attackers to execute arbitrary system commands with root privileges. The flaw stems from improper sanitization of input strings parsed during internal configuration handling.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AIvanti Sentry - Command Injection - CVE:CVE-2026-10520LogBlock

This is a new detection.

Use Cloudforce One threat intelligence in WAF rules

You can now match incoming requests against Cloudforce One threat intelligence in your WAF rules. A new detection looks up the client IP address of each request against the threat intelligence database. If the IP was involved in threat activity in the past seven days, Cloudflare populates cf.intel.ip.* fields that you can use in custom rules and rate limiting rules.

The detection populates the following fields. Use the any() function with the [*] wildcard to match array values:

  • cf.intel.ip.datasets — the dataset that flagged the IP address (ddos or waf).
  • cf.intel.ip.target_industries — industries the IP address has targeted.
  • cf.intel.ip.attacker_names — known threat actors associated with the IP address.
  • cf.intel.ip.attacker_countries — source countries of the threat activity.
  • cf.intel.ip.target_countries — countries the IP address has targeted.

For example, the following custom rule expression blocks requests from IP addresses associated with DDoS activity that have targeted France:

any(cf.intel.ip.target_countries[*] == "FR") and any(cf.intel.ip.datasets[*] == "ddos")

These fields work with the Cloudflare API and Terraform. Matches are logged in Security Analytics.

The threat intelligence detection is available to customers with an active Cloudforce One subscription. For more information, refer to Threat intelligence.

WAF Release - 2026-06-15

This week's release introduces new managed protection to address a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) and a new generic rule designed to identify and block sophisticated SQL Injection (SQLi) bypass attempts leveraging obfuscated boolean logic. These rules protect affected installations from unauthorized data exfiltration at the network edge.

Key Findings

  • CVE-2026-26980: A blind SQL injection vulnerability in the Ghost CMS Content API (versions 3.24.0 to 6.19.0) allows unauthenticated remote attackers to inject malicious SQL commands via query parameters due to improper input validation.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AGhost CMS - SQLi - CVE:CVE-2026-26980LogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Obfuscated Boolean - URILogDisabled

This is a new detection.

WAF Release - 2026-06-09

This release introduces new detections for a critical SQL injection vulnerability in Drupal installations utilizing PostgreSQL (CVE-2026-9082), alongside targeted protection for an unsafe deserialization flaw in the Mirasvit Cache Warmer extension (CVE-2026-45247). Additionally, this release includes coverage for a prototype pollution vector in Axios (CVE-2026-40175) and a new generic rule designed to identify and block sophisticated SQL Injection (SQLi) bypass attempts leveraging obfuscated boolean logic.

Key Findings

  • CVE-2026-9082: A database abstraction vulnerability affects Drupal sites configured with a PostgreSQL backend. Remote, unauthenticated attackers can exploit this flaw via crafted inputs to inject malicious SQL commands and access or manipulate backend data.

  • CVE-2026-45247: A PHP Object Injection vulnerability exists in the Mirasvit Cache Warmer extension for Magento and Adobe Commerce. This flaw stems from unsafe deserialization of untrusted user input, enabling unauthenticated attackers to execute arbitrary code on the hosting server.

  • CVE-2026-40175: A prototype pollution vulnerability affects the Axios HTTP client library. Attackers can exploit this to inject malicious properties into the global JavaScript object prototype, potentially causing application crashes (Denial of Service) or executing unauthorized code depending on the application structure.

Impact

Successful exploitation of these vulnerabilities could allow unauthenticated attackers to execute arbitrary code, manipulate database contents, or induce application crashes, leading to severe operational disruption or complete server compromise. These newly deployed signatures intercept these advanced malicious payloads at the edge before they can interact with vulnerable software configurations.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AAxios - Prototype Pollution - CVE:CVE-2026-40175LogBlock

This is a new detection.

Cloudflare Managed RulesetN/ADrupal - PostgreSQL SQLi - CVE:CVE-2026-9082 - BodyLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ADrupal - PostgreSQL SQLi - CVE:CVE-2026-9082 - URILogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Obfuscated Boolean - BodyN/ADisabled

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Obfuscated Boolean - HeadersN/ADisabled

This is a new detection.

Cloudflare Managed RulesetN/AMirasvit Cache Warmer - PHP Object Injection - CVE:CVE-2026-45247N/ABlock

This is a new detection.

WAF Release - 2026-05-20

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against broad classes of web attacks and strengthen behavioral coverage.

Continuous Rule Improvements

We are continuously refining our managed rules to provide more resilient protection and deeper insights into attack patterns. To ensure an optimal security posture, we recommend consistently monitoring the Security Events dashboard and adjusting rule actions as these enhancements are deployed.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASitecore - Cache Poisoning - CVE:CVE-2025-53693 BetaN/ABlock

This rule is merged into the original rule "Sitecore - Cache Poisoning - CVE:CVE-2025-53693" (ID: ).

WAF Release - 2026-05-15 - Emergency

This emergency release introduces two new rules to detect nginx heap buffer overflow and heap spray exploitation attempts targeting the rewrite module's is_args stale-state bug (CVE-2026-42945).

Key Findings

CVE-2026-42945: nginx Heap Buffer Overflow via Stale is_args in Rewrite Module

Successful exploitation allows remote attackers to trigger a heap buffer overflow in nginx's rewrite module by sending crafted URIs containing escapable characters. A length/copy pass mismatch in ngx_http_script_copy_capture_code() causes the copy pass to write escaped data into an undersized buffer, leading to heap corruption. This enables denial of service (worker process crash) and, with heap feng shui techniques, potential remote code execution.

We strongly recommend upgrading to nginx 1.30.1 (or later) immediately to address the underlying vulnerability. If you cannot upgrade immediately, avoid rewrite directives with ? in the replacement string followed by set or if referencing capture groups.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/Anginx - Remote Code Execution - Buffer Overread - CVE:CVE-2026-42945N/ABlock

This is a new detection.

Cloudflare Managed RulesetN/Anginx - Remote Code Execution - Heap Spray - CVE:CVE-2026-42945N/ABlock

This is a new detection.

WAF Release - 2026-05-11

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against broad classes of web attacks and strengthen behavioral coverage.

Continuous Rule Improvements

We are continuously refining our managed rules to provide more resilient protection and deeper insights into attack patterns. To ensure an optimal security posture, we recommend consistently monitoring the Security Events dashboard and adjusting rule actions as these enhancements are deployed.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ARemote Code Execution - Java Deserialization - Body - BetaBlockDisabled

This is a new detection. This rule is merged into the original rule "Remote Code Execution - Java Deserialization" (ID: ).

WAF and framework adapter mitigations for React and Next.js vulnerabilities

Multiple security vulnerabilities were disclosed by the React team and Vercel affecting React Server Components and Next.js. These include denial of service, middleware and proxy bypass, server-side request forgery, cross-site scripting, and cache poisoning issues across a range of severity levels.

We strongly recommend updating your application and its dependencies immediately. Patched versions are available for React (react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack 19.0.6, 19.1.7, and 19.2.6) and Next.js (15.5.16 and 16.2.5).

WAF protections

Cloudflare WAF rules deployed in response to prior React Server Component CVEs (CVE-2025-55184 and CVE-2026-23864) already provide coverage for the newly disclosed denial-of-service vulnerabilities. These rules are enabled by default with a Block action for all customers using the Cloudflare Managed Ruleset, including Free plan customers using the Free Managed Ruleset.

Ruleset Rule description Rule ID Default action
Cloudflare Managed Ruleset React - DoS - CVE-2025-55184 2694f1610c0b471393b21aef102ec699 Block
Cloudflare Managed Ruleset React - DoS - CVE-2026-23864 aaede80b4d414dc89c443cea61680354 Block

The existing rules detect the underlying attack patterns generically. As a result, they apply to the new CVE-2026-23870 denial-of-service vulnerability in Server Components and the corresponding Next.js advisory GHSA-8h8q-6873-q5fj.

Cloudflare is investigating whether WAF rules can be safely and effectively deployed for three of the high-severity advisories: CVE-2026-23870 / GHSA-8h8q-6873-q5fj, GHSA-267c-6grr-h53f, and GHSA-mg66-mrh9-m8jx. If it is possible to create a managed WAF rule that mitigates these CVEs and does not potentially break application behavior, Cloudflare will add additional managed WAF rules. These rules will be announced through the WAF changelog. Because these vulnerabilities were shared with Cloudflare with minimal advance notice, we are still investigating what WAF mitigations are possible.

Several of the disclosed vulnerabilities are not possible to block in WAF. We strongly recommend updating your applications so they are not purely reliant on WAF mitigations.

Customers on Pro, Business, or Enterprise plans should ensure that Managed Rules are enabled.

Next.js adapters

Vinext: Vinext is a Vite plugin that reimplements the Next.js API surface. Vinext's latest release is not vulnerable to any of the disclosed CVEs. Vinext's architecture differs from stock Next.js in ways that sidestep the affected code paths. For example, it does not implement the PPR resume protocol, does not expose Pages Router data-route endpoints, and strips internal headers such as x-nextjs-data at request boundaries. As an extra layer of defense, we added a React 19.2.6 or later requirement when running vinext init (PR #1118, PR #1112) to prevent accidentally running a vulnerable version of React with Vinext.

OpenNext on Cloudflare: OpenNext is an adapter that lets you deploy Next.js apps to the Cloudflare Workers platform. OpenNext itself is not directly vulnerable to the React denial-of-service CVE, but users must update the Next.js version in their application. The OpenNext team has updated the adapter to further harden against these vectors and released a new version of the Cloudflare adapter. Test fixtures and examples have been updated to use patched versions (PR #1255).

Summary of disclosed vulnerabilities

Advisory Severity Issue WAF status
CVE-2026-23870 / GHSA-8h8q-6873-q5fj High Denial of service in Server Components WAF rules in place: 2694f1610c0b471393b21aef102ec699, aaede80b4d414dc89c443cea61680354
Cloudflare is investigating additional managed WAF coverage
GHSA-267c-6grr-h53f High Middleware bypass via segment-prefetch routes Cloudflare is investigating if this can be safely and effectively mitigated by a managed WAF rule
GHSA-mg66-mrh9-m8jx High Denial of service via connection exhaustion in Cache Components Cloudflare is investigating if this can be safely and effectively mitigated by a managed WAF rule
GHSA-492v-c6pp-mqqv High Middleware bypass via dynamic route parameter injection Not possible to safely enable a managed WAF rule without potentially breaking application behavior
GHSA-c4j6-fc7j-m34r High SSRF via WebSocket upgrades Not possible to safely enable a managed WAF rule without potentially breaking application behavior
GHSA-36qx-fr4f-26g5 High Middleware bypass in Pages Router i18n Custom WAF rule possible; global managed rule could potentially break application behavior
GHSA-ffhc-5mcf-pf4q Moderate XSS via CSP nonces Custom WAF rule possible; global managed rule could potentially break application behavior
GHSA-gx5p-jg67-6x7h Moderate XSS in beforeInteractive scripts Not possible to safely enable a managed WAF rule without potentially breaking application behavior
GHSA-h64f-5h5j-jqjh Moderate Denial of service in Image Optimization API Custom WAF rule possible; global managed rule could potentially break application behavior
GHSA-wfc6-r584-vfw7 Moderate Cache poisoning in RSC responses Custom WAF rule possible; global managed rule could potentially break application behavior
GHSA-vfv6-92ff-j949 Low Cache poisoning via RSC cache-busting collisions Not possible to safely enable a managed WAF rule without potentially breaking application behavior
GHSA-3g8h-86w9-wvmq Low Middleware redirect cache poisoning Custom WAF rule possible; global managed rule could potentially break application behavior

WAF Release - 2026-05-07 - Emergency

This emergency release introduces a new rule to detect Next.js App Router middleware and proxy bypass attempts via segment-prefetch routes (CVE-2026-44575).

Key Findings

CVE-2026-44575: Next.js Middleware / Proxy Bypass in App Router Applications via Segment-Prefetch Routes

Successful exploitation allows unauthenticated attackers to bypass middleware or proxy-based authorization checks in affected Next.js App Router applications. This leads to unauthorized access to protected content, potential exposure of sensitive application data, and compromise of application security boundaries.

We strongly recommend upgrading to Next.js 15.5.16 or 16.2.5 (or later) immediately to address the underlying vulnerability. If you cannot upgrade immediately, enforce authorization in the underlying route or page logic instead of relying solely on middleware.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ANext.js - Middleware Bypass via Invalid RSC Header - CVE:CVE-2026-44575N/ADisabled

This is a new detection.

WAF Release - 2026-05-04

This week's release focuses on new detections to expand coverage across command injection, SQL injection, PHP object injection, remote code execution, and XSS attack vectors.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against broad classes of web attacks and strengthen behavioral coverage.

Continuous Rule Improvements

We are continuously refining our managed rules to provide more resilient protection and deeper insights into attack patterns. To ensure an optimal security posture, we recommend consistently monitoring the Security Events dashboard and adjusting rule actions as these enhancements are deployed.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AXSS, HTML Injection - Object Tag - Body (beta)LogBlock

This is a new detection. This rule is merged into the original rule "XSS, HTML Injection - Object Tag" (ID: ).

Cloudflare Managed RulesetN/AXSS, HTML Injection - Object Tag - HeadersLogBlock

This is a new detection. The rule previously known as "XSS, HTML Injection - Object Tag - Headers (beta)" is now renamed to "XSS, HTML Injection - Object Tag - Headers".

Cloudflare Managed RulesetN/AXSS, HTML Injection - Object Tag - URILogBlock

This is a new detection. The rule previously known as "XSS, HTML Injection - Object Tag - URI (beta)" is now renamed to "XSS, HTML Injection - Object Tag - URI".

Cloudflare Managed RulesetN/ACommand Injection - Generic 9 - Body Vector - BetaN/ADisabled

This is a new detection. This rule is merged into the original rule "Command Injection - Generic 9 - Body Vector" (ID: )

Cloudflare Managed RulesetN/ACommand Injection - Generic 9 - Header Vector - BetaN/ADisabled

This is a new detection. This rule is merged into the original rule "Command Injection - Generic 9 - Header Vector" (ID: )

Cloudflare Managed RulesetN/ACommand Injection - Generic 9 - URI Vector - BetaN/ADisabled

This is a new detection. This rule is merged into the original rule "Command Injection - Generic 9 - URI Vector" (ID: )

Cloudflare Managed RulesetN/ACommand Injection - Sleep - BodyN/ADisabled

This is a new detection. The rule previously known as "Command Injection

  • Sleep" is now renamed to "Command Injection - Sleep - Body".
Cloudflare Managed RulesetN/ACommand Injection - Sleep - HeadersN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/ACommand Injection - Sleep - URIN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/AFortinet FortiSandbox - Command Injection - CVE:CVE-2026-39808LogBlockThis is a new detection.
Cloudflare Managed RulesetN/ARemote Code Execution - Common Bash Bypass - HeadersN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/ARemote Code Execution - Common Bash Bypass - URIN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/ARemote Code Execution - Common Bash Bypass - Body - BetaN/ADisabled

This is a new detection. This rule is merged into the original rule "Remote Code Execution - Common Bash Bypass Body" (ID: ). The rule previously known as "Remote Code Execution - Common Bash Bypass Beta" is now renamed to "Remote Code Execution - Common Bash Bypass Body".

Cloudflare Managed RulesetN/APHP Object Injection - 2 - Body - BetaN/ADisabled

This is a new detection. This rule is merged into the original rule "PHP Object Injection - 2" (ID: )

Cloudflare Managed RulesetN/APHP Object Injection - 2 - HeadersN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/APHP Object Injection - 2 - URIN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - DROP - 2 - BetaN/ADisabled

This is a new detection. This rule is merged into the original rule "SQLi - DROP - 2" (ID: )

Cloudflare Managed RulesetN/ASQLi - DROP - 2 - HeadersN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - DROP - 2 - URIN/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/ASmarterMail - Remote Code Execution - CVE:CVE-2026-24423LogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - SELECT Expression - BodyBlockDisabledAction changed
Cloudflare Managed RulesetN/ASQLi - String Concatenation - URIBlockDisabledAction changed

WAF Release - 2026-04-30 - Emergency

This emergency release introduces a new rule to block a cPanel & WHM Authentication Bypass related to CVE-2026-41940.

Key Findings

  • CVE-2026-41940: A critical authentication bypass vulnerability in cPanel & WHM allows unauthenticated remote attackers to bypass authentication mechanisms and gain unauthorized administrative access to the web hosting control panel. This vulnerability affects the session validation logic, enabling attackers to craft malicious requests that circumvent normal authentication checks.

Impact

Successful exploitation allows unauthenticated attackers to gain administrative control over affected cPanel & WHM installations. This leads to complete server compromise, potential theft or manipulation of hosted data, and significant service disruption across managed environments.

We strongly recommend applying official vendor patches for cPanel & WHM immediately to address the underlying vulnerability.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AcPanel - Auth Bypass - CVE:CVE-2026-41940N/ABlockThis is a new detection.

WAF Release - 2026-04-27

This week's release focuses on new improvements to enhance coverage.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against broad classes of web attacks and strengthen behavioral coverage.

Continuous Rule Improvements

We are continuously refining our managed rules to provide more resilient protection and deeper insights into attack patterns. To ensure an optimal security posture, we recommend consistently monitoring the Security Events dashboard and adjusting rule actions as these enhancements are deployed.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/APostgreSQL - SQLi - COPY - BetaLogBlock

This is a new detection. This rule is merged into the original rule "PostgreSQL - SQLi - COPY - Body (ID: ). The rule previously known as "PostgreSQL - SQLi - COPY" is now renamed to "PostgreSQL - SQLi - COPY - Body".

Cloudflare Managed RulesetN/APostgreSQL - SQLi - COPY - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/APostgreSQL - SQLi - COPY - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - AND/OR MAKE_SET/ELT - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - AND/OR MAKE_SET/ELT - Body" (ID: ). The rule previously known as "SQLi - AND/OR MAKE_SET/ELT" is now renamed to "SQLi - AND/OR MAKE_SET/ELT - Body".

Cloudflare Managed RulesetN/ASQLi - AND/OR MAKE_SET/ELT - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - AND/OR MAKE_SET/ELT - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Common Patterns - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - Common Patterns - Body" (ID: ). The rule previously known as "SQLi - Common Patterns" is now renamed to "SQLi - Common Patterns - Body".

Cloudflare Managed RulesetN/ASQLi - Common Patterns - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Common Patterns - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Equation - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - Equation - Body" (ID: ). The rule previously known as "SQLi - Equation" is now renamed to "SQLi - Equation - Body".

Cloudflare Managed RulesetN/ASQLi - Equation - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Equation - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - AND/OR Digit Operator Digit - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - AND/OR Digit Operator Digit - Body" (ID: ). The rule previously known as "SQLi - AND/OR Digit Operator Digit" is now renamed to "SQLi - AND/OR Digit Operator Digit - Body".

Cloudflare Managed RulesetN/ASQLi - AND/OR Digit Operator Digit - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - AND/OR Digit Operator Digit - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Benchmark Function - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - Benchmark Function - Body" (ID: ). The rule previously known as "SQLi - Benchmark Function" is now renamed to "SQLi - Benchmark Function - Body".

Cloudflare Managed RulesetN/ASQLi - Benchmark Function - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Benchmark Function - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Comparison - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - Comparison - Body" (ID: ). The rule previously known as "SQLi - Comparison" is now renamed to "SQLi - Comparison - Body".

Cloudflare Managed RulesetN/ASQLi - Comparison - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Comparison - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - String Concatenation - Body - BetaLogBlockThis is a new detection. This rule is merged into the original rule "SQLi - String Concatenation - Headers" (ID: ).The rule previously known as "SQLi - String Concatenation - Headers" is now renamed to "SQLi - String Concatenation - Body".
Cloudflare Managed RulesetN/ASQLi - String Concatenation - HeadersLogBlockThis is a new detection.(Former Id was )
Cloudflare Managed RulesetN/ASQLi - String Concatenation - URILogBlockThis is a new detection. (Former Id was )
Cloudflare Managed RulesetN/ASQLi - SELECT Expression - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - SELECT Expression - Body" (ID: ). The rule previously known as "SQLi - SELECT Expression" is now renamed to "SQLi - SELECT Expression - Body".

Cloudflare Managed RulesetN/ASQLi - SELECT Expression - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - SELECT Expression - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - ORD and ASCII - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - ORD and ASCII- Body" (ID: ). The rule previously known as "SQLi - ORD and ASCII" is now renamed to "SQLi - ORD and ASCII- Body".

Cloudflare Managed RulesetN/ASQLi - ORD and ASCII - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - ORD and ASCII - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Destructive OperationsLogBlockThis is a new detection.

WAF Release - 2026-04-21

This week's release introduces a new detection for a Remote Code Execution (RCE) vulnerability in Apache ActiveMQ (CVE-2026-34197) and an updated signature for Magento 2 - Unrestricted File Upload. Alongside these detections, we are continuing our work on rule refinements to provide deeper security insights for our customers.

Key Findings

  • Apache ActiveMQ (CVE-2026-34197): A vulnerability in Apache ActiveMQ allows an unauthenticated, remote attacker to execute arbitrary code. This flaw occurs during the processing of specially crafted network packets, leading to potential full system compromise.

  • Magento 2 - Unrestricted File Upload - 2: This is a follow-up enhancement to our existing protections for Magento and Adobe Commerce.

Impact

Successful exploitation of these vulnerabilities could allow unauthenticated attackers to execute arbitrary code or gain full administrative control over affected servers. We strongly recommend applying official vendor patches for Apache ActiveMQ and Magento to address the underlying vulnerabilities.

Continuous Rule Improvements

We are continuously refining our managed rules to provide more resilient protection and deeper insights into attack patterns. To ensure an optimal security posture, we recommend consistently monitoring the Security Events dashboard and adjusting rule actions as these enhancements are deployed.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ACommand Injection - Generic 8 - uriLogBlockThis is a new detection. Previous description was "Command Injection - Generic 8 - uri - Beta"
Cloudflare Managed RulesetN/ACommand Injection - Generic 8 - body - BetaDisabledDisabled

This is a new detection. This rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ). The rule previously known as "Command Injection - Generic 8" is now renamed to "Command Injection - Generic 8 - body".

Cloudflare Managed RulesetN/AMySQL - SQLi - Executable Comment - BetaLogBlock

This is a new detection. This rule is merged into the original rule "MySQL - SQLi - Executable Comment - Body" (ID: ) The rule previously known as "MySQL - SQLi - Executable Comment" is now renamed to "MySQL - SQLi - Executable Comment - Body".

Cloudflare Managed RulesetN/AMySQL - SQLi - Executable Comment - HeadersLogBlock

This is a new detection.

Cloudflare Managed RulesetN/AMySQL - SQLi - Executable Comment - URILogBlock

This is a new detection.

Cloudflare Managed RulesetN/AMagento 2 - Unrestricted file upload - 2LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AApache ActiveMQ - Remote Code Execution - CVE:CVE-2026-34197LogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Sleep Function - BetaLogBlock

This is a new detection. This rule is merged into the original rule "SQLi - Sleep Function" (ID: )

Cloudflare Managed RulesetN/ASQLi - Sleep Function - HeadersLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Sleep Function - URILogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Probing - uriLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Probing - headerLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASQLi - Probing - bodyDisabledDisabled

This is a new detection. This rule is merged into the original rule "SQLi - Probing" (ID: )

Cloudflare Managed RulesetN/ASQLi - Probing 2 DisabledDisabled

This rule had duplicate detection logic and has been deprecated.

Cloudflare Managed RulesetN/ASQLi - UNION in MSSQL - BodyDisabledDisabled

This rule has been renamed to differentiate from "SQLi - UNION in MSSQL" (ID: ) and contains updated rule logic.

Cloudflare Managed RulesetN/ASQLi - UNION - 3DisabledDisabled

This rule had duplicate detection logic and has been deprecated.

Cloudflare Managed RulesetN/AXSS, HTML Injection - Embed Tag - URIDisabledDisabled

This is a new detection.

Cloudflare Managed RulesetN/AXSS, HTML Injection - Embed Tag - HeadersLogBlock

This is a new detection.

Cloudflare Managed RulesetN/AXSS, HTML Injection - IFrame Tag - Src and Srcdoc Attributes - HeadersLogDisabled

This is a new detection.

Cloudflare Managed RulesetN/AXSS, HTML Injection - Link Tag - HeadersLogDisabled

This is a new detection.

Cloudflare Managed RulesetN/AXSS, HTML Injection - Link Tag - URIDisabledDisabled

This is a new detection.

WAF Release - 2026-04-15

This week's release introduces a new detection for a critical Remote Code Execution (RCE) vulnerability in Mesop (CVE-2026-33057), alongside protections for high-impact vulnerabilities in Cisco Secure Firewall Management Center (CVE-2026-20079) and FortiClient EMS (CVE-2026-21643). Additionally, this release includes an update to our existing React Server DoS coverage to address recently identified resource exhaustion vectors (CVE-2026-23869).

Key Findings

  • Cisco Secure FMC (CVE-2026-20079): A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) that allows an unauthenticated, remote attacker to execute arbitrary commands or bypass security filters.

  • FortiClient EMS (CVE-2026-21643): A critical vulnerability in the FortiClient EMS permitting unauthorized access or administrative configuration manipulation via crafted HTTP requests.

  • Mesop (CVE-2026-33057): A vulnerability in the Mesop Python-based UI framework where unauthenticated attackers can execute arbitrary code by sending specially crafted, Base64-encoded payloads in the request body.

Impact

Successful exploitation of these vulnerabilities could allow unauthenticated attackers to execute arbitrary code, gain administrative control over network management infrastructure, or trigger server-side resource exhaustion. Administrators are strongly encouraged to apply official vendor updates.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ACisco Secure FMC - RCE via upgradeReadinessCall - CVE:CVE-2026-20079LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AFortiClient EMS - Pre-Auth SQL Injection - CVE:CVE-2026-21643LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AMesop - Remote Code Execution - Base64 Payload - CVE:CVE-2026-33057LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AReact Server - DOS - CVE:CVE-2026-23864 - 1 - BetaLogBlockThis rule has been merged into the original rule "React Server - DOS - CVE:CVE-2026-23864 - 1" (ID: )
Cloudflare Managed RulesetN/AXSS, HTML Injection - Link Tag - URI (beta)N/ADisabledThis is a new detection.
Cloudflare Managed RulesetN/AXSS, HTML Injection - Embed Tag - URI (beta)N/ADisabledThis is a new detection.

Email obfuscation decode script is now non-render-blocking

The decode script injected by Email Address Obfuscation now loads with the defer attribute. This means the script no longer blocks page rendering. It downloads in parallel with HTML parsing and executes after the document is fully parsed, before the DOMContentLoaded event.

This improves page loading performance, contributing to better Core Web Vitals, for all zones with Email Address Obfuscation on. No action is required.

If you have custom JavaScript that depends on email addresses being decoded at a specific point during page load, note that the decode script now executes after HTML parsing completes rather than inline during parsing.

WAF Release - 2026-04-07

This week's release introduces new detections for a critical Remote Code Execution (RCE) vulnerability in MCP Server (CVE-2026-23744), alongside targeted protection for an authentication bypass vulnerability in SolarWinds products (CVE-2025-40552). Additionally, this release includes a new generic detection rule designed to identify and block Cross-Site Scripting (XSS) injection attempts leveraging "OnEvent" handlers within HTTP cookies.

Key Findings

  • MCP Server (CVE-2026-23744): A vulnerability in the Model Context Protocol (MCP) server implementation where malformed input payloads can trigger a memory corruption state, allowing for arbitrary code execution.

  • SolarWinds (CVE-2025-40552): A critical flaw in the authentication module allows unauthenticated attackers to bypass security filters and gain unauthorized access to the management console due to improper identity token validation.

  • XSS OnEvents Cookies: This generic rule identifies malicious event handlers (such as onload or onerror) embedded within HTTP cookie values.

Impact

Successful exploitation of the MCP Server and SolarWinds vulnerabilities could allow unauthenticated attackers to execute arbitrary code or gain administrative control, leading to a full system takeover. Additionally, the new generic XSS detection prevents attackers from leveraging browser event handlers in cookies to hijack user sessions or execute malicious scripts.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - 5 - BodyLogDisabledThis is a new detection.
Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - 5 - HeaderLogDisabledThis is a new detection.
Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - 5 - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/AMCP Server - Remote Code Execution - CVE:CVE-2026-23744LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS - OnEvents - CookiesLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Evasion - BodyLogDisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Evasion - HeadersLogDisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - Evasion - URILogDisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - LIKE 3 - BodyLogDisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - LIKE 3 - URILogDisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - UNION - 2 - BodyLogDisabledThis is a new detection.
Cloudflare Managed RulesetN/ASQLi - UNION - 2 - URILogDisabledThis is a new detection.
Cloudflare Managed RulesetN/ASolarWinds - Auth Bypass - CVE:CVE-2025-40552LogBlockThis is a new detection.

WAF Release - 2026-03-30

This week's release introduces new detections for a critical authentication bypass vulnerability in Fortinet products (CVE-2025-59718), alongside three new generic detection rules designed to identify and block HTTP Parameter Pollution attempts. Additionally, this release includes targeted protection for a high-impact unrestricted file upload vulnerability in Magento and Adobe Commerce.

Key Findings

  • CVE-2025-59718: An improper cryptographic signature verification vulnerability in Fortinet FortiOS, FortiProxy, and FortiSwitchManager. This may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication using a maliciously crafted SAML message, if that feature is enabled on the device.

  • Magento 2 - Unrestricted File Upload: A critical flaw in Magento and Adobe Commerce allows unauthenticated attackers to bypass security checks and upload malicious files to the server, potentially leading to Remote Code Execution (RCE).

Impact

Successful exploitation of the Fortinet and Magento vulnerabilities could allow unauthenticated attackers to gain administrative control or deploy webshells, leading to complete server compromise and data theft.



RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AGeneric Rules - Parameter Pollution - BodyLogDisabledThis is a new detection.
Cloudflare Managed RulesetN/A Generic Rules - Parameter Pollution - Header - Form Log Disabled This is a new detection.
Cloudflare Managed RulesetN/A Generic Rules - Parameter Pollution - URI Log Disabled This is a new detection.
Cloudflare Managed RulesetN/AMagento 2 - Unrestricted file uploadLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AFortinet FortiCloud SSO - Authentication Bypass - CVE:CVE-2025-59718LogBlockThis is a new detection.