releases.sh

Cloudflare One

Mon
Wed
Fri
AugSepOctNovDecJanFebMarAprMayJunJulAug
Less
More
Releases64Avg Interval34hAvg Cadence21/mo

Cloudflare Access administrators can now control whether a self-hosted application preemptively sets authorization cookies across its public hostnames, replacing the previous automatic behavior based on hostname count. The new Eager redirect cookie setting is on by default for new applications but can be turned off to avoid sign-in loops in browsers.

Read more →
v2026.7.1210

Connection reliability improved by swapping protocol order after repeated QUIC/HTTP/3 failures. Fixes include a MASQUE tunnel stall during high-rate upload, inability to switch organizations when stuck in "Device not in organization" state, orphaned credentials on multi-user uninstall, certificate errors on connection, and DNS search domain parsing failures. Post-re-authentication now re-evaluates device profiles.

Read more →
v2026.7.1210

Fixed a MASQUE tunnel stall during high-rate uploads, a crash during dialog dismissal, and a hang preventing organization switching when stuck in "Device not in organization" state. Also improved connection reliability with protocol-order swapping after repeated connectivity-check failures, plus a dozen other fixes across DNS, captive portal, and UI.

Read more →

Admins can now set a maximum TTL for DNS responses returned by Gateway, capping overridden upstream TTLs to ensure policy changes take effect faster. The setting is available at the account level and per DNS location, with two new DNS log fields for upstream and applied TTL values.

Read more →
v2026.6.880

Fixed a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Read more →
v2026.6.880

Fixed a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Read more →

Users in browser-based RDP sessions can now copy multiple PDF files to the clipboard on the remote machine and select Print all PDFs to combine them into a single PDF sent to the local printer. Available in Chromium-based browsers and Firefox.

Read more →

Internal DNS, providing authoritative and recursive DNS for private networks on the same global network and control plane as public DNS, Zero Trust, and application services, is now generally available. It consolidates DNS operations, simplifies split-horizon DNS, and extends Zero Trust to DNS via resolver policies.

Read more →

Data Loss Prevention source code detection now evaluates whole source code file uploads and downloads instead of performing partial scans, eliminating false positives from code embedded in chat messages, documentation, and code samples. A 500-character minimum threshold filters out small fragments, and confidence levels let operators tune match sensitivity.

Read more →

On October 5, 2026, CIDR-encoded route endpoints for the Zero Trust Networks API are removed in favor of route_id-based endpoints, and the connections field is removed from Cloudflare Tunnel and Mesh list and get responses—migrate to dedicated connections endpoints instead. Scripts, cloudflared, and Terraform configurations managing routes or reading tunnel connection details must be updated before the removal date.

Read more →

Cloudflare IPsec now supports the IKE_SA_INIT_FULL_TRANSCRIPT_AUTH IKEv2 extension to protect against downgrade attacks that exploit quantum-capable attackers bypassing post-quantum key exchange. The feature is available in beta for Cloudflare WAN and Magic Transit IPsec tunnels, gated by a per-account feature flag.

Read more →
v2026.6.850

Fixed a Windows authentication issue in the embedded WebView2 browser where single sign-on could fail to use the Windows primary account, causing users to be prompted for interactive sign-in. The embedded authentication browser now allows SSO providers to use the OS primary account when available.

Read more →

Cloudflare Access now allows administrators to configure per-policy file transfer controls for browser-based RDP sessions, with options to allow uploads only, downloads only, both directions, or disable file transfers entirely. File transfer is denied by default for new policies and remains denied for existing applications.

Read more →
Latest
Aug 3, 2026