Releases Index

Cloudflare One

$npx @buildinternet/releases get cloudflare-one
Mon
Wed
Fri
SepOctNovDecJanFebMarAprMayJunJulAugSep
Less
More
Releases74Avg Interval32hAvg Cadence23/mo

Access for Infrastructure now integrates with Resource Tagging, letting you attach key-value tags to infrastructure targets and use them in access policies, managed inline on a target or via the central Resource Tagging API with tags kept in sync across both. Target criteria support include, require, and exclude operators that each match by hostname, tag, or both.

Read more →

Cloudflare Access can request fresh authentication from a SAML identity provider on every login by enabling Require reauthentication in the dashboard or setting force_authn to true via the API, which makes Access set ForceAuthn to true in signed and unsigned SAML authentication requests. The option defaults to false.

Read more →

Passive Detection for Cloudflare Data Loss Prevention samples Gateway HTTP request and response bodies to surface sensitive data types and their destinations, without requiring a Gateway DLP policy. Existing Gateway policies continue to apply, and available detection entries depend on the account's Zero Trust plan.

Read more →

Cloudflare CASB now integrates with Zoom through Cloudflare's pre-built OAuth application, requiring no manual app setup, and continuously scans accounts for findings after an initial scan. Scans cover account settings, user accounts, meetings, recordings, and sensitive content via DLP Profile matching.

Read more →

DHCP options can now be configured directly from the dashboard when the Cloudflare One Appliance acts as the LAN's DHCP server, complementing the existing API and Terraform workflow. Options include common PXE/iPXE boot, VoIP provisioning, and vendor-specific settings, or custom option codes.

Read more →

You can now create multiple Cloudflare Tunnel and Cloudflare Mesh routes from the Routes page in a single action, instead of submitting one at a time. When creating a route you can add multiple destinations as a comma-separated list, queue up additional routes before creating them all together, and retry only the routes that failed in a batch since successful ones are removed from the form automatically.

Read more →

Service token Client Secrets created on or after August 26, 2026 use the cfast_ prefix plus checksum format, improving detection by secret scanning tools. Existing secrets continue to work without rotation, and both formats use the same Client ID and authentication headers.

Read more →

Access administrators can now disable service tokens without deleting them; disabled tokens can't authenticate but retain their configuration for later re-enabling, and disabling also stops any previous secret in an active rotation grace period. Useful for containing suspected credential exposure or pausing an automated service.

Read more →

Cloudflare Access administrators can now choose a grace period when rotating a service token secret, keeping both secrets valid during the transition instead of interrupting authentication. Grace periods range from one hour to 30 days in the dashboard, with immediate revocation available and RFC 3339 expiration times for the API.

Read more →

MCP server portals now support the stateless MCP 2026-07-28 specification for both client and upstream connections. The /mcp endpoint auto-accepts stateless requests and falls back to the 2025 handshake when needed; client and upstream protocol selection are independent, and SSE continues to use the legacy protocol.

Read more →

When registering a Cloudflare One Virtual Appliance, you can now select your hypervisor and download the appliance directly from the dashboard — no need to look up asset URLs. Choose from VMware ESXi (OVA image), Proxmox, or libvirt/KVM (install script), and use View setup guide for deployment instructions.

Read more →

CASB remediation policies can automatically revoke or remediate Microsoft 365 and Google Workspace file-sharing findings without manual triage. Policies can also send webhooks to third-party destinations, and both actions can be combined in a single policy.

Read more →

Test scan checks how Data Loss Prevention evaluates sample content—paste text, upload a file or HAR file—before applying a profile to production traffic. Content goes directly to the DLP scanner, so Gateway policies are not evaluated and no Gateway activity logs are created. Available to all Cloudflare Zero Trust customers.

Read more →
Latest
Sep 15, 2026