Releases Index

Cloudflare One Changelog

$npx @buildinternet/releases get cloudflare-cloudflare-one
Mon
Wed
Fri
OctNovDecJanFebMarAprMayJunJulAugSepOct
Less
More
Releases84Avg26/moVersionsv2026.6.850 to v2026.8.2100
v2026.8.2100

The macOS Cloudflare One Client is now generally available, keeping its learned split tunnel configuration across reconnects so excluded resources are no longer briefly blocked while connecting. It also routes non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled, shares a single hosts file read across DNS resolvers for faster connects and lower memory use, and includes an MDM setting to prefer IPv4 in proxy mode, off by default.

Read more →
v2026.8.2100

The Windows Cloudflare One Client is now generally available. Traffic to split tunnel excluded resources is no longer briefly blocked during connect or reconnect since the client retains its learned split tunnel configuration across tunnel reconnections, and non-RFC 1918 local IPv4 networks can be routed through the tunnel when unrestricted LAN inclusion is enabled by policy or MDM. The release also adds a scheduled task that restarts the client service on system unlock if it is not running, and fixes reauthentication forcing a new registration, reconnects during Emergency Disconnect, and a UI stuck in connecting state after sleep and wake.

Read more →
v2026.8.2100

The Cloudflare One Client for Linux reaches general availability, keeping learned split tunnel configuration across reconnects so excluded resources are no longer briefly blocked while connecting. Also adds routing of non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled, an MDM setting to prefer IPv4 in proxy mode (off by default), faster reconnects with lower memory use from a shared hosts file, and a long list of fixes covering reauthentication, MTU handling, DNS-over-HTTPS timeouts, and several client crashes.

Read more →

Cloudflare Organizations is generally available for Enterprise customers and MSSP/Distributor partners, providing a top-level container for centrally managing accounts, members, analytics, and shared policies with Super Administrators granted implicit access to every account in the Organization. Enterprise customers use single-tier Organizations while MSSP/Distributor partners can use nested sub-organizations; Organization Roles remains in beta.

Read more →

Cloudflare CASB now supports custom finding types, letting security teams write their own detection logic in Rego evaluated against asset data from connected integrations. Custom finding types can target any supported provider and asset class, are validated before creation, and work with CASB remediation policies.

Read more →

BGP peering over IPsec and GRE tunnels is generally available for Cloudflare WAN and Magic Transit, allowing routes to be exchanged dynamically between customer devices and the Cloudflare virtual network routing table instead of updating static routes manually. It is available to all accounts using Unified Routing with no enablement required, while BGP over CNI remains in closed beta.

Read more →

A new strict service token authentication setting makes Access return 401 or 403 instead of redirecting to the login page on failed service token requests, authorizes only via Service Auth policies, and stops issuing CF_Authorization cookies. Zero Trust organizations created on or after October 5, 2026 have it on by default and cannot disable it.

Read more →

Tagging infrastructure targets through the Infrastructure Access Targets API now requires only the Zero Trust Write API token permission, previously needing both Zero Trust Write and Tag Write. Tagging through the general Resource Tagging API still requires Tag Admin, Tag Write, or an equivalent role.

Read more →
v2026.8.2033

Fixed slow captive portal checks that could make the client service unresponsive or restart during connect, and a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting. Also improved reauthentication reliability, DNS over lower-MTU networks, and added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled.

Read more →

Isolation policies now support role-based access control, since they are Gateway HTTP policies with the Isolate action. The Zero Trust HTTP Policies Admin account-level role grants access to all HTTP policies, and resource-scoped roles let team members manage a specific isolation policy without exposing other Gateway resources.

Read more →
v2026.8.2028

The Windows Cloudflare One Client beta fixes an issue that could briefly block traffic to split tunnel excluded resources while connecting or reconnecting, and a reauthentication bug that could force a new registration. Also adds routing of non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM, and fixes startup and DEX TLS validation crashes.

Read more →
v2026.8.2028

A macOS beta of the Cloudflare One Client fixes brief traffic blocking to split tunnel excluded resources during connect or reconnect, stops reauthentication from forcing a new registration, and adds support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled. Plus fixes for captive portal and DNS enforcement checks freezing the client service, IPv6-only DNS connectivity checks, and two startup and UI crashes.

Read more →

Gateway network logs and the zero_trust_network_sessions Logpush dataset add OnrampType values for MESH and WORKERS_VPC, SourceName/SourceID fields identifying which Worker started a session, and DestinationReplicaID showing which Cloudflare Tunnel or cloudflared replica received it. SourceName and SourceID only populate for Workers deployed or redeployed after 29 September 2026, and sessions logged before this change are not backfilled.

Read more →

MCP server portals, which give users a single endpoint for approved Model Context Protocol servers with Access logging of tool, prompt, and resource activity, are now generally available to all Cloudflare customers. Since the open beta they added Gateway routing for HTTP logging and DLP scanning, Code Mode policies, static OAuth client credentials, session management, service token authentication, and Logpush export.

Read more →

Cloudflare Mesh now supports adding participants from the dashboard via Add participant under Networking > Mesh, covering Mesh node deployment on Linux, Kubernetes, Docker Compose, and Docker CLI, plus platform-specific Cloudflare One Client installers and mobile QR codes. Mesh nodes and enrolled client devices now appear in a unified participant table with search, type and status filters, and per-source loading that keeps one source available if the other fails.

Read more →

Gateway HTTP and Network policies now include a Traffic Destination selector, exposed as the net.offramp.type API field, that identifies how traffic exits Cloudflare so administrators can target off-ramp methods. Available values are internet, cloudflare_wan, cloudflare_tunnel, device_client, and mesh.

Read more →

Access administrators can set an inactivity period from 30 to 365 days and choose whether tokens that reach the limit are disabled or deleted. Tokens are eligible only if they are older than the configured period, have not successfully authenticated during it, and are not directly referenced by an Access policy rule; cleanup runs gradually in the background.

Read more →

MCP server portals can now connect to MCP servers available only on a private network, routing through Cloudflare Gateway to private hostnames and IP addresses without exposing the server to the public Internet. Connect the server network via Cloudflare Tunnel, Cloudflare Mesh, or another Cloudflare One connector, configure a private hostname or CIDR route, and enable Route traffic through Cloudflare Gateway when adding the server; OAuth authorization and token endpoints must remain publicly accessible.

Read more →
v2026.8.1755

Beta release for the macOS client fixes reauthentication forcing a new registration, traffic briefly blocked to split tunnel excluded resources during connect or reconnect, and DNS connectivity checks failing on IPv6-only networks. Also adds routing of non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled, and fixes a startup crash when system locale date formatting data has not loaded.

Read more →
Last Checked
2h ago
Tracking since May 18, 2025