releases.shpreview

Cloudflare One

Mon
Wed
Fri
JulAugSepOctNovDecJanFebMarAprMayJunJul
Less
More
Releases73Avg Interval32hAvg Cadence22/mo

Users in browser-based RDP sessions can now copy multiple PDF files to the clipboard on the remote machine and select Print all PDFs to combine them into a single PDF sent to the local printer. Available in Chromium-based browsers and Firefox.

Read more →

Internal DNS, providing authoritative and recursive DNS for private networks on the same global network and control plane as public DNS, Zero Trust, and application services, is now generally available. It consolidates DNS operations, simplifies split-horizon DNS, and extends Zero Trust to DNS via resolver policies.

Read more →

Data Loss Prevention source code detection now evaluates whole source code file uploads and downloads instead of performing partial scans, eliminating false positives from code embedded in chat messages, documentation, and code samples. A 500-character minimum threshold filters out small fragments, and confidence levels let operators tune match sensitivity.

Read more →

On October 5, 2026, CIDR-encoded route endpoints for the Zero Trust Networks API are removed in favor of route_id-based endpoints, and the connections field is removed from Cloudflare Tunnel and Mesh list and get responses—migrate to dedicated connections endpoints instead. Scripts, cloudflared, and Terraform configurations managing routes or reading tunnel connection details must be updated before the removal date.

Read more →

Cloudflare IPsec now supports the IKE_SA_INIT_FULL_TRANSCRIPT_AUTH IKEv2 extension to protect against downgrade attacks that exploit quantum-capable attackers bypassing post-quantum key exchange. The feature is available in beta for Cloudflare WAN and Magic Transit IPsec tunnels, gated by a per-account feature flag.

Read more →
v2026.6.850

Fixed a Windows authentication issue in the embedded WebView2 browser where single sign-on could fail to use the Windows primary account, causing users to be prompted for interactive sign-in. The embedded authentication browser now allows SSO providers to use the OS primary account when available.

Read more →

Cloudflare Access now allows administrators to configure per-policy file transfer controls for browser-based RDP sessions, with options to allow uploads only, downloads only, both directions, or disable file transfers entirely. File transfer is denied by default for new policies and remains denied for existing applications.

Read more →

Browser Isolation now supports Gateway authorization proxy endpoints, allowing you to apply HTTP Isolate policies to traffic routed through them. This enables identity-based Isolate policies on PAC file-proxied traffic without requiring the Cloudflare One Client, whereas previously only source IP proxy endpoints supported Browser Isolation with non-identity policies.

Read more →

Virtual Appliance registration and license key generation are now available directly in the dashboard without contacting the account team. Users can register appliances, generate and rotate authentication keys, and manage connectors from the Connectors page.

Read more →

Eight new resource-scoped roles allow delegating access to specific Gateway policy types (DNS, HTTP, Network, Egress, Resolver) or Zero Trust lists without granting account-wide control. Existing account-level roles remain fully backward compatible.

Read more →
v2026.6.822

Client now applies DNS search suffixes from device profiles or network policies, and device registration tokens can be generated in the Secure Enclave for hardware-backed security. Also adds a local-file signal source for Emergency Disconnect, DNSSEC passthrough in the DNS proxy, a new MDM format, and dashboard-managed client version deployments. Fixes include underscore-containing hostnames in proxy mode, captive-portal blank-page rendering, idle DNS failures, and support for case-insensitive team names. PMTUD is now enabled by default.

Read more →
v2026.6.782

Registration tokens can now be generated in the Secure Enclave to provide stronger protection against device impersonation. The release also fixes DNS query failures after idle connections, improves accessibility with high contrast colors, enables Path MTU Discovery by default, and adds UI improvements including re-auth prompts, split tunnel configuration visibility, and proxy mode configuration for consumer users.

Read more →

Regional Services now supports Regionalized IP Bindings, letting you bind a CIDR from a BYOIP prefix to a region for IP-layer traffic regionalization. Requires Regional Services and Regional Services for BYOIP entitlements.

Read more →
Latest
Jul 16, 2026