New Cloudflare Managed Ruleset detection for CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP that allows arbitrary code execution, now blocks instead of logging. Command Injection - Generic 8 - uri beta logic is merged into the baseline rule and moves from log to block, and the Next.js cache poisoning rule description was refined with no detection change.
Application Security Changelog
npx @buildinternet/releases get cloudflare-application-securityCloudflare Managed Ruleset adds a new block rule for CVE-2026-88771, an improper input validation flaw in Citrix NetScaler ADC and Gateway that allows an unauthenticated attacker to execute arbitrary commands. Administrators are advised to apply the latest Citrix versions and review configurations against applicable preconditions.
New managed ruleset detections for GitLab path traversal CVE-2026-85706 and broken access control directory traversal switch from log to block, and a new rule blocks generic request routing cache inconsistency. Beta HTTP request smuggling and command injection rules are merged into their original rules.
Cloudflare's managed ruleset adds blocking rules for CVE-2026-87902, a WordPress path traversal and local file inclusion flaw, and CVE-2026-42018 and CVE-2026-82329, authentication bypass vulnerabilities in JFrog Artifactory. The release also adds a WordPress comment XSS detection and recommends administrators apply the latest vendor patches.
Four new Cloudflare Managed Ruleset detections move from Log to Block: SSRF via cloud/link-local and local non-standard IP notations, SSRF via jar HTTP loopback payloads, and SSTI targeting Jinja dangerous globals chains.
Enterprise Bot Management customers can control whether Cloudflare uses results created through the JavaScript Detections API for bot scoring and detections, via the JavaScript Detections for API traffic setting in Security Settings or the jsd_api_results_enabled field on the Bot Management API. The setting is separate from zone-wide script injection, so when it is off the API script still executes and returns success to the callback but the result is not consumed.
New WAF detections for command injection, SSRF targeting cloud metadata, and information disclosure in version control history move from log to block in the Cloudflare Managed Ruleset. The version control rule is merged into the existing "Version Control - Information Disclosure" rule.
New Cloudflare Managed Ruleset rule (CVE-2026-75650, "StyleSmuggler") blocks unauthenticated remote code execution in Adobe Commerce and Magento Open Source template engine. Cloudflare says the edge rule is virtual patching only and origin applications must still apply the Adobe hotfix and rotate exposed encryption keys, integration tokens, and system credentials.
Consolidated active beta rules into baseline signatures for Next.js RCE vulnerabilities, changing two managed rules from Log to Block. This covers image optimizer AVIF exploitation and CVE-2026-75604.
Application Profiles add a positive-security layer to Cloudflare WAF that learns valid request structure — path variables, query parameters, headers, cookies, JSON bodies, and form-encoded bodies — and classifies requests as conforming or non-conforming without blocking traffic. Schema Profiles are available to API Security customers and via a closed beta for invited Enterprise customers, with Profile Analysis in Security Analytics and Custom Rules for scoping enforcement.
Attack Signature Detection is available in Early Access, evaluating requests against Cloudflare attack signatures and recording matches without applying a mitigation action so detected traffic can be investigated first. Matches surface in Security Analytics under Attack Analysis with signature references, categories, confidence levels, and request outcomes, and can be used in Security Rules alongside hostname, path, and HTTP method for scoped mitigation.
Adds a new threat detection to the Cloudflare Managed Ruleset, improving coverage for SQL injection patterns combining WHERE comparisons with WITH clauses. The new rule, SQLi - WHERE Comparison With WITH Clause, transitions from Log to Block action.
API Shield now supports 32 JWT token configurations per zone by default, up from the previous limit, with each configuration holding up to 16 keys. The added capacity supports more configurations and key rotation.
Emergency WAF release updates an existing rule to identify CVE-2026-75604, covering Windows-hosted Next.js apps on both Pages and App Router, and adds a new detection for remote code execution in the Next.js Image Optimizer via crafted AVIF images.
Four new detections move from Log to Block in the Cloudflare Managed Ruleset, including HTTP/2 Request Smuggling and XSS JavaScript Event Handler Coercion across Headers, Body, and URI. A new Generic Rules - Remote Code Execution detection is added in Block mode, and the XSS, HTML Injection - Script Tag - Beta rule merges into the original rule.
API Shield JWT validation now supports symmetric keys using HS256, HS384, and HS512 algorithms, configurable via the Cloudflare dashboard or API. Credentials are never stored in plaintext and are excluded from API responses.
Leaked credentials detection automatically scans Authorization headers for Basic Authentication credentials, decoding them and comparing against Cloudflare's leaked credential database. Matches populate existing fields and trigger the Exposed-Credential-Check header if configured; no configuration changes required.
Cloudflare updated the metadata for the WordPress remote code execution rule in the Managed and Free rulesets to identify CVE-2026-65640, an unauthenticated RCE vulnerability allowing arbitrary command execution and backdoor installation. Detection behavior and actions remain unchanged.
New Cloudflare Managed Ruleset detection blocks vBulletin CVE-2026-61511, a remote code execution vulnerability. Two beta detections for Version Control information disclosure and vBulletin code injection have been merged into existing rules and upgraded from Log to Block action.
Turnstile Spin is now generally available with three ways to create a widget and wire server-side siteverify: via the Turnstile dashboard, the Wrangler CLI, or an AI coding agent. The agent setup includes insertion snippets for Next.js, Astro, SvelteKit, Hugo, and vanilla HTML, and runs a real token test through the protected endpoint to validate the integration.
