Releases Index

Application Security Changelog

$npx @buildinternet/releases get cloudflare-application-security
Mon
Wed
Fri
OctNovDecJanFebMarAprMayJunJulAugSepOct
Less
More
Releases27Avg8/mo

New Cloudflare Managed Ruleset detection for CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP that allows arbitrary code execution, now blocks instead of logging. Command Injection - Generic 8 - uri beta logic is merged into the baseline rule and moves from log to block, and the Next.js cache poisoning rule description was refined with no detection change.

Read more →

Cloudflare Managed Ruleset adds a new block rule for CVE-2026-88771, an improper input validation flaw in Citrix NetScaler ADC and Gateway that allows an unauthenticated attacker to execute arbitrary commands. Administrators are advised to apply the latest Citrix versions and review configurations against applicable preconditions.

Read more →

New managed ruleset detections for GitLab path traversal CVE-2026-85706 and broken access control directory traversal switch from log to block, and a new rule blocks generic request routing cache inconsistency. Beta HTTP request smuggling and command injection rules are merged into their original rules.

Read more →

Cloudflare's managed ruleset adds blocking rules for CVE-2026-87902, a WordPress path traversal and local file inclusion flaw, and CVE-2026-42018 and CVE-2026-82329, authentication bypass vulnerabilities in JFrog Artifactory. The release also adds a WordPress comment XSS detection and recommends administrators apply the latest vendor patches.

Read more →

Four new Cloudflare Managed Ruleset detections move from Log to Block: SSRF via cloud/link-local and local non-standard IP notations, SSRF via jar HTTP loopback payloads, and SSTI targeting Jinja dangerous globals chains.

Read more →

Enterprise Bot Management customers can control whether Cloudflare uses results created through the JavaScript Detections API for bot scoring and detections, via the JavaScript Detections for API traffic setting in Security Settings or the jsd_api_results_enabled field on the Bot Management API. The setting is separate from zone-wide script injection, so when it is off the API script still executes and returns success to the callback but the result is not consumed.

Read more →

New WAF detections for command injection, SSRF targeting cloud metadata, and information disclosure in version control history move from log to block in the Cloudflare Managed Ruleset. The version control rule is merged into the existing "Version Control - Information Disclosure" rule.

Read more →

New Cloudflare Managed Ruleset rule (CVE-2026-75650, "StyleSmuggler") blocks unauthenticated remote code execution in Adobe Commerce and Magento Open Source template engine. Cloudflare says the edge rule is virtual patching only and origin applications must still apply the Adobe hotfix and rotate exposed encryption keys, integration tokens, and system credentials.

Read more →

Application Profiles add a positive-security layer to Cloudflare WAF that learns valid request structure — path variables, query parameters, headers, cookies, JSON bodies, and form-encoded bodies — and classifies requests as conforming or non-conforming without blocking traffic. Schema Profiles are available to API Security customers and via a closed beta for invited Enterprise customers, with Profile Analysis in Security Analytics and Custom Rules for scoping enforcement.

Read more →

Attack Signature Detection is available in Early Access, evaluating requests against Cloudflare attack signatures and recording matches without applying a mitigation action so detected traffic can be investigated first. Matches surface in Security Analytics under Attack Analysis with signature references, categories, confidence levels, and request outcomes, and can be used in Security Rules alongside hostname, path, and HTTP method for scoped mitigation.

Read more →

Adds a new threat detection to the Cloudflare Managed Ruleset, improving coverage for SQL injection patterns combining WHERE comparisons with WITH clauses. The new rule, SQLi - WHERE Comparison With WITH Clause, transitions from Log to Block action.

Read more →

Emergency WAF release updates an existing rule to identify CVE-2026-75604, covering Windows-hosted Next.js apps on both Pages and App Router, and adds a new detection for remote code execution in the Next.js Image Optimizer via crafted AVIF images.

Read more →

Four new detections move from Log to Block in the Cloudflare Managed Ruleset, including HTTP/2 Request Smuggling and XSS JavaScript Event Handler Coercion across Headers, Body, and URI. A new Generic Rules - Remote Code Execution detection is added in Block mode, and the XSS, HTML Injection - Script Tag - Beta rule merges into the original rule.

Read more →

Leaked credentials detection automatically scans Authorization headers for Basic Authentication credentials, decoding them and comparing against Cloudflare's leaked credential database. Matches populate existing fields and trigger the Exposed-Credential-Check header if configured; no configuration changes required.

Read more →

Cloudflare updated the metadata for the WordPress remote code execution rule in the Managed and Free rulesets to identify CVE-2026-65640, an unauthenticated RCE vulnerability allowing arbitrary command execution and backdoor installation. Detection behavior and actions remain unchanged.

Read more →

New Cloudflare Managed Ruleset detection blocks vBulletin CVE-2026-61511, a remote code execution vulnerability. Two beta detections for Version Control information disclosure and vBulletin code injection have been merged into existing rules and upgraded from Log to Block action.

Read more →

Turnstile Spin is now generally available with three ways to create a widget and wire server-side siteverify: via the Turnstile dashboard, the Wrangler CLI, or an AI coding agent. The agent setup includes insertion snippets for Next.js, Astro, SvelteKit, Hugo, and vanilla HTML, and runs a real token test through the protected endpoint to validate the integration.

Read more →
Last Checked
43m ago
Tracking since Jan 6, 2025