Users in browser-based RDP sessions can now copy multiple PDF files to the clipboard on the remote machine and select Print all PDFs to combine them into a single PDF sent to the local printer. Available in Chromium-based browsers and Firefox.
Cloudflare One
Internal DNS, providing authoritative and recursive DNS for private networks on the same global network and control plane as public DNS, Zero Trust, and application services, is now generally available. It consolidates DNS operations, simplifies split-horizon DNS, and extends Zero Trust to DNS via resolver policies.
Data Loss Prevention source code detection now evaluates whole source code file uploads and downloads instead of performing partial scans, eliminating false positives from code embedded in chat messages, documentation, and code samples. A 500-character minimum threshold filters out small fragments, and confidence levels let operators tune match sensitivity.
On October 5, 2026, CIDR-encoded route endpoints for the Zero Trust Networks API are removed in favor of route_id-based endpoints, and the connections field is removed from Cloudflare Tunnel and Mesh list and get responses—migrate to dedicated connections endpoints instead. Scripts, cloudflared, and Terraform configurations managing routes or reading tunnel connection details must be updated before the removal date.
Cloudflare IPsec now supports the IKE_SA_INIT_FULL_TRANSCRIPT_AUTH IKEv2 extension to protect against downgrade attacks that exploit quantum-capable attackers bypassing post-quantum key exchange. The feature is available in beta for Cloudflare WAN and Magic Transit IPsec tunnels, gated by a per-account feature flag.
Fixed a Windows authentication issue in the embedded WebView2 browser where single sign-on could fail to use the Windows primary account, causing users to be prompted for interactive sign-in. The embedded authentication browser now allows SSO providers to use the OS primary account when available.
Cloudflare Access now allows administrators to configure per-policy file transfer controls for browser-based RDP sessions, with options to allow uploads only, downloads only, both directions, or disable file transfers entirely. File transfer is denied by default for new policies and remains denied for existing applications.
Browser Isolation now supports Gateway authorization proxy endpoints, allowing you to apply HTTP Isolate policies to traffic routed through them. This enables identity-based Isolate policies on PAC file-proxied traffic without requiring the Cloudflare One Client, whereas previously only source IP proxy endpoints supported Browser Isolation with non-identity policies.
Virtual Appliance registration and license key generation are now available directly in the dashboard without contacting the account team. Users can register appliances, generate and rotate authentication keys, and manage connectors from the Connectors page.
Cloudflare Mesh nodes can now route traffic using hostnames (private or public) instead of CIDR ranges, with Gateway rewriting the destination to a private IP.
RPM packages now serve builds specific to each OS version, preventing installs from pulling unavailable dependencies. Debian and Ubuntu were not affected. Users on RPM-based distros should refresh their repo configuration.
Cloudflare Access for Infrastructure now supports independent multi-factor authentication for SSH connections using YubiKey PIV keys, adding a hardware-backed second factor that a compromised device session alone cannot bypass. MFA requirements can be configured per application, per policy, and per username.
Access now correctly preserves URL fragment characters when redirecting users back to an application after login, fixing broken navigation for single-page applications that use fragment-based routes.
Eight new resource-scoped roles allow delegating access to specific Gateway policy types (DNS, HTTP, Network, Egress, Resolver) or Zero Trust lists without granting account-wide control. Existing account-level roles remain fully backward compatible.
Client now applies DNS search suffixes from device profiles or network policies, and device registration tokens can be generated in the Secure Enclave for hardware-backed security. Also adds a local-file signal source for Emergency Disconnect, DNSSEC passthrough in the DNS proxy, a new MDM format, and dashboard-managed client version deployments. Fixes include underscore-containing hostnames in proxy mode, captive-portal blank-page rendering, idle DNS failures, and support for case-insensitive team names. PMTUD is now enabled by default.
Mandatory authentication blocks all traffic until user authenticates, closing a visibility gap on newly deployed devices. Device registration now uses TPM 2.0+ for stronger protection against impersonation. DNSSEC passthrough, DNS search suffixes from device profiles, and a local-file emergency disconnect source are also new.
GA release brings DNS search suffixes from device profiles, hardware-backed TPM 2.0+ device registration, local-file Emergency Disconnect signal, and DNSSEC passthrough for the local DNS proxy. Also fixes underscore-containing hostnames in proxy mode and blank captive-portal pages on airline Wi-Fi.
Access service tokens can now connect autonomous agents to MCP server portals without a browser-based OAuth flow. Requires Service Auth policies for both the portal and each linked MCP server, with per-user OAuth turned off.
Registration tokens can now be generated in the Secure Enclave to provide stronger protection against device impersonation. The release also fixes DNS query failures after idle connections, improves accessibility with high contrast colors, enables Path MTU Discovery by default, and adds UI improvements including re-auth prompts, split tunnel configuration visibility, and proxy mode configuration for consumer users.
Regional Services now supports Regionalized IP Bindings, letting you bind a CIDR from a BYOIP prefix to a region for IP-layer traffic regionalization. Requires Regional Services and Regional Services for BYOIP entitlements.