New WAF detections for command injection, SSRF targeting cloud metadata, and information disclosure in version control history move from log to block in the Cloudflare Managed Ruleset. The version control rule is merged into the existing "Version Control - Information Disclosure" rule.
Application Security
npx @buildinternet/releases get application-securityNew Cloudflare Managed Ruleset rule (CVE-2026-75650, "StyleSmuggler") blocks unauthenticated remote code execution in Adobe Commerce and Magento Open Source template engine. Cloudflare says the edge rule is virtual patching only and origin applications must still apply the Adobe hotfix and rotate exposed encryption keys, integration tokens, and system credentials.
Consolidated active beta rules into baseline signatures for Next.js RCE vulnerabilities, changing two managed rules from Log to Block. This covers image optimizer AVIF exploitation and CVE-2026-75604.
Adds a new threat detection to the Cloudflare Managed Ruleset, improving coverage for SQL injection patterns combining WHERE comparisons with WITH clauses. The new rule, SQLi - WHERE Comparison With WITH Clause, transitions from Log to Block action.
Emergency WAF release updates an existing rule to identify CVE-2026-75604, covering Windows-hosted Next.js apps on both Pages and App Router, and adds a new detection for remote code execution in the Next.js Image Optimizer via crafted AVIF images.
Four new detections move from Log to Block in the Cloudflare Managed Ruleset, including HTTP/2 Request Smuggling and XSS JavaScript Event Handler Coercion across Headers, Body, and URI. A new Generic Rules - Remote Code Execution detection is added in Block mode, and the XSS, HTML Injection - Script Tag - Beta rule merges into the original rule.
API Shield JWT validation now supports symmetric keys using HS256, HS384, and HS512 algorithms, configurable via the Cloudflare dashboard or API. Credentials are never stored in plaintext and are excluded from API responses.
Leaked credentials detection automatically scans Authorization headers for Basic Authentication credentials, decoding them and comparing against Cloudflare's leaked credential database. Matches populate existing fields and trigger the Exposed-Credential-Check header if configured; no configuration changes required.
Cloudflare updated the metadata for the WordPress remote code execution rule in the Managed and Free rulesets to identify CVE-2026-65640, an unauthenticated RCE vulnerability allowing arbitrary command execution and backdoor installation. Detection behavior and actions remain unchanged.
vBulletin RCE CVE blocked; two detections upgraded to Block
Breaking (minor)New Cloudflare Managed Ruleset detection blocks vBulletin CVE-2026-61511, a remote code execution vulnerability. Two beta detections for Version Control information disclosure and vBulletin code injection have been merged into existing rules and upgraded from Log to Block action.
Turnstile Spin is now generally available with three ways to create a widget and wire server-side siteverify: via the Turnstile dashboard, the Wrangler CLI, or an AI coding agent. The agent setup includes insertion snippets for Next.js, Astro, SvelteKit, Hugo, and vanilla HTML, and runs a real token test through the protected endpoint to validate the integration.
XSS2Shell detection metadata added; obfuscation rule disabled
Breaking (minor)WordPress XSS rule metadata in the Cloudflare Managed and Free Rulesets now identifies XSS2Shell (CVE-2026-64638); detection behavior itself is unchanged. The Command Injection - Obfuscation rule is disabled in the Managed Ruleset as its detection logic has been deprecated.
New rules block CVE-2026-50522 (SharePoint Server RCE) and update a rule for CVE-2026-66066 (Rails Active Storage RCE). Added SSRF detection for cloud-hosted applications with a new Block action, removing several older SSRF beta rules.
New rules block unauthenticated remote code execution in Nuxt Server Islands and Alibaba Fastjson ≤1.2.83 deserialization. Also promoted SSRF detection for cloud metadata and obfuscated command injection from Log to Block, and added new generic RCE, XSS, and file-upload rules.
New rules block CVEs in Adobe ColdFusion (path traversal) and WordPress (SQL injection and RCE). Existing SSRF, LFI, and XSS obfuscation detections now default to Block, and new generic rules cover unauthenticated RCE, auth bypass, and information disclosure.
Four new managed rules block active exploitation of a critical remote code execution and SQL injection vulnerability in popular web frameworks, applied to both Cloudflare Managed and Free rulesets.
New WAF rules block unauthenticated memory disclosure in Citrix NetScaler ADC (CVE-2026-8451) and pre-authentication remote code execution in Progress Kemp LoadMaster (CVE-2026-8037). Both rules log by default and block on detection.
Precursor, a client-side JavaScript that enables session-based bot detection, is rolling out to all customers. It continuously evaluates behavioral signals across a session, re-validates challenge clearance as behavior changes, and updates bot scores with session context.
Cloudflare groups AI crawlers into three behaviors—Search, Agent, and Training—that customers on all plans can control independently. Starting September 15, 2026, new domains default to blocking Training and Agent on ad pages while Search remains allowed.
Added a new rule to block path traversal attacks targeting Fortinet FortiSandbox (CVE‑2026‑39813). The Anomaly:Header:User‑Agent — Fake Bing or MSN Bot rule was disabled (previously set to Block), indicating a high false‑positive rate.