Releases Index

Application Security

$npx @buildinternet/releases get application-security
Mon
Wed
Fri
SepOctNovDecJanFebMarAprMayJunJulAugSep
Less
More
Releases25Avg Interval4dAvg Cadence8/mo

New WAF detections for command injection, SSRF targeting cloud metadata, and information disclosure in version control history move from log to block in the Cloudflare Managed Ruleset. The version control rule is merged into the existing "Version Control - Information Disclosure" rule.

Read more →

New Cloudflare Managed Ruleset rule (CVE-2026-75650, "StyleSmuggler") blocks unauthenticated remote code execution in Adobe Commerce and Magento Open Source template engine. Cloudflare says the edge rule is virtual patching only and origin applications must still apply the Adobe hotfix and rotate exposed encryption keys, integration tokens, and system credentials.

Read more →

Adds a new threat detection to the Cloudflare Managed Ruleset, improving coverage for SQL injection patterns combining WHERE comparisons with WITH clauses. The new rule, SQLi - WHERE Comparison With WITH Clause, transitions from Log to Block action.

Read more →

Emergency WAF release updates an existing rule to identify CVE-2026-75604, covering Windows-hosted Next.js apps on both Pages and App Router, and adds a new detection for remote code execution in the Next.js Image Optimizer via crafted AVIF images.

Read more →

Four new detections move from Log to Block in the Cloudflare Managed Ruleset, including HTTP/2 Request Smuggling and XSS JavaScript Event Handler Coercion across Headers, Body, and URI. A new Generic Rules - Remote Code Execution detection is added in Block mode, and the XSS, HTML Injection - Script Tag - Beta rule merges into the original rule.

Read more →

Leaked credentials detection automatically scans Authorization headers for Basic Authentication credentials, decoding them and comparing against Cloudflare's leaked credential database. Matches populate existing fields and trigger the Exposed-Credential-Check header if configured; no configuration changes required.

Read more →

Cloudflare updated the metadata for the WordPress remote code execution rule in the Managed and Free rulesets to identify CVE-2026-65640, an unauthenticated RCE vulnerability allowing arbitrary command execution and backdoor installation. Detection behavior and actions remain unchanged.

Read more →

New Cloudflare Managed Ruleset detection blocks vBulletin CVE-2026-61511, a remote code execution vulnerability. Two beta detections for Version Control information disclosure and vBulletin code injection have been merged into existing rules and upgraded from Log to Block action.

Read more →

Turnstile Spin is now generally available with three ways to create a widget and wire server-side siteverify: via the Turnstile dashboard, the Wrangler CLI, or an AI coding agent. The agent setup includes insertion snippets for Next.js, Astro, SvelteKit, Hugo, and vanilla HTML, and runs a real token test through the protected endpoint to validate the integration.

Read more →

WordPress XSS rule metadata in the Cloudflare Managed and Free Rulesets now identifies XSS2Shell (CVE-2026-64638); detection behavior itself is unchanged. The Command Injection - Obfuscation rule is disabled in the Managed Ruleset as its detection logic has been deprecated.

Read more →

Precursor, a client-side JavaScript that enables session-based bot detection, is rolling out to all customers. It continuously evaluates behavioral signals across a session, re-validates challenge clearance as behavior changes, and updates bot scores with session context.

Read more →
Latest
Sep 15, 2026