Cloudflare Access administrators can now control whether a self-hosted application preemptively sets authorization cookies across its public hostnames, replacing the previous automatic behavior based on hostname count. The new Eager redirect cookie setting is on by default for new applications but can be turned off to avoid sign-in loops in browsers.
Cloudflare One
Connection reliability improved by swapping protocol order after repeated QUIC/HTTP/3 failures. Fixes include a MASQUE tunnel stall during high-rate upload, inability to switch organizations when stuck in "Device not in organization" state, orphaned credentials on multi-user uninstall, certificate errors on connection, and DNS search domain parsing failures. Post-re-authentication now re-evaluates device profiles.
Fixed a MASQUE tunnel stall during high-rate uploads, a crash during dialog dismissal, and a hang preventing organization switching when stuck in "Device not in organization" state. Also improved connection reliability with protocol-order swapping after repeated connectivity-check failures, plus a dozen other fixes across DNS, captive portal, and UI.
MCP server portals now support connecting to upstream servers that require a pre-registered OAuth client, with admin-configurable client ID, secret, custom endpoints, and scopes.
Admins can now set a maximum TTL for DNS responses returned by Gateway, capping overridden upstream TTLs to ensure policy changes take effect faster. The setting is available at the account level and per DNS location, with two new DNS log fields for upstream and applied TTL values.
Fixed a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.
Fixed a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.
Fixed a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated.
Plaintext HTTP private apps on port 80 now use the standard browser-based login flow with an Access application token, replacing the previous Cloudflare One Client notification-based session. No configuration change is required.
Cloudflare One Appliances can now be restarted, rebooted, or shut down directly from the dashboard or via API. Restart purges temporary and optionally persistent state; reboot power-cycles and re-applies configuration; shutdown powers off the appliance.
Gateway HTTP Allow policies now support adding, overwriting, and deleting request headers using static values or dynamic variables from identity, device, and network context.
Users in browser-based RDP sessions can now copy multiple PDF files to the clipboard on the remote machine and select Print all PDFs to combine them into a single PDF sent to the local printer. Available in Chromium-based browsers and Firefox.
Internal DNS, providing authoritative and recursive DNS for private networks on the same global network and control plane as public DNS, Zero Trust, and application services, is now generally available. It consolidates DNS operations, simplifies split-horizon DNS, and extends Zero Trust to DNS via resolver policies.
Data Loss Prevention source code detection now evaluates whole source code file uploads and downloads instead of performing partial scans, eliminating false positives from code embedded in chat messages, documentation, and code samples. A 500-character minimum threshold filters out small fragments, and confidence levels let operators tune match sensitivity.
On October 5, 2026, CIDR-encoded route endpoints for the Zero Trust Networks API are removed in favor of route_id-based endpoints, and the connections field is removed from Cloudflare Tunnel and Mesh list and get responses—migrate to dedicated connections endpoints instead. Scripts, cloudflared, and Terraform configurations managing routes or reading tunnel connection details must be updated before the removal date.
Device Monitoring now analyzes hardware and network data between a Cloudflare One Client device and Cloudflare's edge, with per-category health summaries (Connection, Wi-Fi signal strength, Traffic performance, Device health) and time-range filtering. Available to all Cloudflare One customers at no additional cost.
Cloudflare IPsec now supports the IKE_SA_INIT_FULL_TRANSCRIPT_AUTH IKEv2 extension to protect against downgrade attacks that exploit quantum-capable attackers bypassing post-quantum key exchange. The feature is available in beta for Cloudflare WAN and Magic Transit IPsec tunnels, gated by a per-account feature flag.
IP lists, IDS, and SIP rules are now supported for accounts using Unified Routing mode, requiring a Cloudflare Advanced Network Firewall subscription.
Fixed a Windows authentication issue in the embedded WebView2 browser where single sign-on could fail to use the Windows primary account, causing users to be prompted for interactive sign-in. The embedded authentication browser now allows SSO providers to use the OS primary account when available.
Cloudflare Access now allows administrators to configure per-policy file transfer controls for browser-based RDP sessions, with options to allow uploads only, downloads only, both directions, or disable file transfers entirely. File transfer is denied by default for new policies and remains denied for existing applications.