Zum Inhalt springen

Application Security Updates & Release Notes

28 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Application Security, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-10-06: Schutz vor F5 BIG-IP CVE-2026-94127

Neue Erkennung für den Heap-Overflow CVE-2026-94127 in F5 BIG-IP (Block), die Beta-Regel „Command Injection - Generic 8 - uri“ wird in die Originalregel überführt und die Next.js-Cache-Poisoning-Beschreibung wurde nur in den Metadaten präzisiert.

This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule.

Key Findings

  • CVE-2026-94127: A heap-based buffer overflow vulnerability in F5 BIG-IP. Attackers can exploit this flaw to execute arbitrary code on the affected system.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...a056caff

N/A

Command Injection - Generic 8 - uri - Beta

Log

Block

This rule is merged into the original rule "Command Injection - Generic 8 - uri" (ID: ...ee159e2e).

Cloudflare Managed Ruleset

...7206c737

N/A

F5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...549f7356

N/A

Next.js - Cache Poisoning - CVE:CVE-2026-94543

Block

Block

Rule metadata description refined. Detection unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF: Geplante Änderung für 2026-10-12

Die Regel „Generic Rules - Template Injection - 2 - Beta“ wird zum 2026-10-12 deaktiviert und in die Originalregel „Generic Rules - Template Injection - 2“ überführt.

Announcement Date

Release Date

Release Behavior

Legacy Rule ID

Rule ID

Description

Comments

2026-10-06

2026-10-12

Disable

N/A

...02751ef3

Generic Rules - Template Injection - 2 - Beta

This rule will be merged into the original rule "Generic Rules - Template Injection - 2" (ID: ...d3ed0123).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Emergency Release 2026-10-01: Citrix NetScaler CVE-2026-88771

Eine neue Regel im Cloudflare Managed Ruleset blockiert Angriffe auf die Schwachstelle CVE-2026-88771 (unzureichende Eingabevalidierung) in Citrix NetScaler ADC und Gateway.

This update provides immediate defense against a vulnerability affecting Citrix NetScaler ADC and Gateway appliances, deploying protection against improper input validation vectors.

Key Findings

  • CVE-2026-88771: An improper input validation vulnerability affecting Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to execute arbitrary commands.

Impact

We strongly recommend that administrators apply the latest versions to fully secure origin servers. Additionally, customers should review configurations against applicable preconditions and follow standard incident response processes if signs of compromise are identified.

Detailed Rule Changes

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...827ab216

N/A

Citrix Netscaler ADC and Gateway - Improper input validation - CVE:CVE-2026-88771

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-09-30: GitLab Path Traversal und Generic Rules

Neue Erkennungen für die GitLab-Schwachstelle CVE-2026-85706, Directory Traversal und Request-Routing-Cache-Inkonsistenzen, außerdem werden Beta-Regeln zu HTTP Request Smuggling und Command Injection in die Originalregeln überführt.

This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.

Key Findings

  • CVE-2026-85706: A path traversal vulnerability affecting GitLab.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...cb14ded8

N/A

Broken Access Control - Directory Traversal

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...0364bd7e

N/A

HTTP Request Smuggling - Request Body Anomaly - Beta

Log

Block

This rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ...1489d892).

Cloudflare Managed Ruleset

...d498a69a

N/A

Command Injection - Generic 8 - body - Beta

Disabled

Disabled

This rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ...413592e2).

Cloudflare Managed Ruleset

...87ae8cfc

N/A

GitLab - Path Traversal- CVE:CVE-2026-85706

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...549f7356

N/A

Generic - Request routing cache inconsistency

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Emergency Release 2026-09-25: WordPress und JFrog Artifactory

Neue Block-Regeln schützen vor Path Traversal/LFI (CVE-2026-87902) und XSS in WordPress sowie vor Authentifizierungsumgehung in JFrog Artifactory (u. a. CVE-2026-42018).

This update provides immediate defense against critical vulnerabilities affecting WordPress and JFrog Artifactory, including path traversal, local file inclusion (LFI), cross-site scripting (XSS), and authentication bypass exploits.

Key Findings

  • CVE-2026-87902: A high-severity Path Traversal and Local File Inclusion (LFI) vulnerability affecting WordPress. Unauthenticated attackers can exploit this flaw to read arbitrary files on the host server, potentially exposing sensitive configuration data or system files.

  • CVE-2026-42018 & CVE-2026-82329: Critical authentication bypass vulnerabilities affecting JFrog Artifactory. Successful exploitation allows unauthenticated attackers to bypass security controls and achieve unauthorized access to the Artifactory instance.

Impact

We strongly recommend that administrators apply the latest vendor patches for WordPress and JFrog Artifactory to fully secure origin servers.

Detailed Rule Changes

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...70a43f96

N/A

Wordpress - Path Traversal, Local File Inclusion - CVE:CVE-2026-87902

N/A

Block

This is a new detection.

Cloudflare Managed Ruleset

...909a4db4

N/A

Wordpress - XSS - Comment

N/A

Block

This is a new detection.

Cloudflare Managed Ruleset

...c797ef03

N/A

JFrog Artifactory - Authentication Bypass - CVE:CVE-2026-42018

N/A

Block

This is a new detection. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-09-22: Neue SSRF- und SSTI-Erkennungen

Vier neue Erkennungen gegen SSRF mit nicht standardmäßiger IP-Notation und jar-Loopback-Payloads sowie gegen Jinja-SSTI wechseln von Log auf Block.

This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...5f21b651

N/A

SSRF - Cloud,Link-Local non-standard IP notation

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...0f0313d6

N/A

SSRF - Block jar HTTP loopback payload

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...75cd912a

N/A

SSRF - Local non-standard IP notation

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...a1ba83f6

N/A

SSTI - Jinja Dangerous Globals Chain

Log

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Bots: JavaScript-Detections-API-Ergebnisse steuerbar

Enterprise-Bot-Management-Kunden können unter Security > Settings oder per jsd_api_results_enabled in der Bot Management API festlegen, ob Cloudflare die Ergebnisse der JavaScript Detections API für Bot-Scoring und Erkennungen nutzt.

Enterprise Bot Management customers can control whether Cloudflare uses results created through the JavaScript Detections API for bot scoring and detections.

Turn JavaScript Detections for API traffic on or off in Security > Settings. You can also configure the zone through the Bot Management API by setting jsd_api_results_enabled:

{
	"jsd_api_results_enabled": true
}

This setting is separate from zone-wide script injection. When it is off, the API script can still execute and return success to the callback, but Cloudflare does not consume the result.

For more information, refer to JavaScript Detections.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-09-15: SSRF, Command Injection, Version Control

Neue Erkennungen für SSRF auf Cloud-Metadaten und Command Injection (Generic 10) wechseln von Log auf Block, zudem wird die Beta-Regel „Version Control - Information Disclosure“ in die Originalregel überführt.

This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...ca453d31

N/A

SSRF - Cloud - 3

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...e540f17f

N/A

Version Control - Information Disclosure - Beta

Log

Block

This rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529).

Cloudflare Managed Ruleset

...ba458b4b

N/A

Command Injection - Generic 10

Log

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Emergency Release 2026-09-10: Adobe Commerce/Magento RCE

Eine neue Block-Regel schützt vor der aktiv ausgenutzten RCE-Schwachstelle CVE-2026-75650 in Adobe Commerce und Magento Open Source, ersetzt aber nicht das Einspielen des Hotfixes aus APSB26-146.

This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts.

Key Findings

  • Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmuggler"): Unauthenticated Remote Code Execution (RCE) vulnerability caused by improper neutralization of special elements in the platform's template engine. Unauthenticated attackers can inject arbitrary PHP payloads through style properties to execute system commands and deploy persistent malware.

Impact

This emergency rule provides immediate edge-level mitigation and virtual patching, origin applications must be urgently updated. We strongly recommend to apply the hotfix outlined in Adobe Security Bulletin APSB26-146 and immediately rotate all potentially exposed encryption keys, integration tokens, and system credentials, as patching alone does not remediate an existing compromise.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...440f5c55

N/A

Adobe Commerce - Remote Code Execution - CVE:CVE-2026-75650

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-09-08: Next.js-RCE-Beta-Regeln zusammengeführt

Die Beta-Regeln zu Next.js Image Optimizer RCE via AVIF und CVE-2026-75604 werden in die jeweiligen Originalregeln überführt und von Log auf Block gesetzt.

This release enhances detection logic for existing rules targeting Next.js remote code execution (RCE) vulnerabilities by consolidating active beta rules into baseline signatures.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...c76ba662

N/A

Next.js - Image Optimizer Remote Code Execution via Crafted AVIF - Beta

Log

Block

This rule is merged into the original rule "Next.js - Image Optimizer Remote Code Execution via Crafted AVIF" (ID: ...80256efe).

Cloudflare Managed Ruleset

...208457cf

N/A

Next.js - Remote Code Execution - CVE:CVE-2026-75604 - Beta

Log

Block

This rule is merged into the original rule "Next.js - Remote Code Execution - CVE:CVE-2026-75604" (ID: ...2ca6cce3).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF: Application Profiles für Positive Security

Application Profiles ergänzen die WAF um eine Positive-Security-Ebene, bei der Schema Profiles gültige Anfragen lernen und abweichenden Traffic ohne Blockierung klassifizieren, wobei die Durchsetzung per Custom Rule erfolgt und für Enterprise-Kunden ohne API Security eine geschlossene Beta startet.

Application Profiles add a positive-security layer to Cloudflare WAF. Instead of looking only for requests that resemble known attacks, Application Profiles learn what valid requests to your application look like and identify traffic that deviates from the expected structure.

The first available profile type, Schema Profiles, can learn path variables, query parameters, headers, cookies, JSON bodies, and form-encoded bodies. Profiles model field types and constraints such as numeric ranges, string lengths, and character classes. After a profile becomes available, an always-on detection classifies requests as conforming or non-conforming without blocking traffic.

Use Profile Analysis in Security Analytics to review conformance trends and sampled violation details before enforcing a profile. When you are ready to mitigate traffic, use a Custom Rule to scope enforcement by hostname, path, operation, or other security signals such as Attack Score.

Customers with API Security already have access to Schema Profiles through Schema Learning and Schema Validation. Cloudflare is also opening a closed beta to invited Enterprise customers without API Security. Contact your Cloudflare account team to express interest.

For more information, refer to Application Profiles.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF: Attack Signature Detection im Early Access

Attack Signature Detection ist im Early Access verfügbar, gleicht Anfragen mit Cloudflare-Angriffssignaturen ab und protokolliert Treffer in Security Analytics > Attack Analysis, ohne Maßnahmen anzuwenden.

Attack Signature Detection is now available in Early Access. It evaluates requests against Cloudflare attack signatures and records matches without applying a mitigation action, allowing you to investigate detected traffic before deciding how to respond.

In Security Analytics > Attack Analysis, you can review matching signature references, categories, confidence levels, and request outcomes. You can then use these fields in Security Rules and combine them with request properties such as hostname, path, and HTTP method to apply scoped mitigation.

Attack Signature Detection uses the same signature definitions as Cloudflare Managed Rules, but it does not inherit your Managed Rules actions, overrides, or deployment configuration. Managed Rules remain the recommended baseline protection during Early Access.

Contact your Cloudflare account team to request access. For more information, refer to Attack Signature Detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-09-01: Neue SQLi-Erkennung

Die neue Erkennung „SQLi - WHERE Comparison With WITH Clause“ wechselt von Log auf Block und verbessert den Schutz vor SQL-Injection mit komplexer Abfragesyntax.

This release introduces a new threat detection to enhance protection against SQL injection (SQLi) attempts exploiting complex query syntax.

Key Findings

  • SQLi Protection: Improved coverage for SQL injection patterns involving WHERE comparisons combined with WITH clauses.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...bcfa0966

N/A

SQLi - WHERE Comparison With WITH Clause

Log

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

API Shield: Höhere Limits für JWT-Validierungskonfigurationen

Die JWT-Validierung in API Shield unterstützt nun standardmäßig 32 Token-Konfigurationen pro Zone mit jeweils bis zu 16 Schlüsseln.

API Shield JSON Web Token validation now supports 32 token configurations per zone by default. Each token configuration can contain up to 16 keys.

These increased limits support more JWT configurations and provide additional capacity for key rotation.

Refer to Configure JWT validation via the API for configuration details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Emergency Release 2026-08-26: Next.js RCE und Image Optimizer

Die bestehende Next.js-RCE-Regel erkennt nun CVE-2026-75604 und eine neue Block-Regel schützt vor RCE im Next.js Image Optimizer über manipulierte AVIF-Bilder.

This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images.

Key Findings

  • CVE-2026-75604 affects Windows-hosted Next.js applications using both the Pages Router and App Router without Cache Components and can lead to unauthenticated remote code execution.

  • GHSA-2xp9-vwfh-vxw4 affects the Next.js Image Optimizer and can lead to unauthenticated remote code execution when it optimizes an attacker-controlled AVIF image.

Impact

Next.js recommends updating to version 16.3.3 or 15.5.24 to address these vulnerabilities.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...2ca6cce3

N/A

Next.js - Remote Code Execution - CVE:CVE-2026-75604

Block

N/A

Rule metadata description refined. Detection unchanged.

Cloudflare Managed Ruleset

...80256efe

N/A

Next.js - Image Optimizer Remote Code Execution via Crafted AVIF

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

API Shield: Symmetrische Schlüssel für JWT-Validierung

Die JWT-Validierung in API Shield unterstützt jetzt symmetrische Schlüssel mit HS256, HS384 und HS512, die im Dashboard oder per API konfiguriert werden können.

API Shield JSON Web Token validation now supports symmetric keys that use the HS256, HS384, and HS512 algorithms. You can configure HMAC verification keys in the Cloudflare dashboard or with the Cloudflare API.

Cloudflare never stores symmetric credentials in plaintext. API responses do not include the credential.

Refer to Configure JWT validation via the API for supported key formats and credential requirements.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-08-25: Mehrere Regeln auf Block, neue RCE-Regel

Vier Erkennungen (HTTP/2 Request Smuggling und XSS-Event-Handler-Coercion) wechseln von Log auf Block, die Beta-Regel „XSS, HTML Injection - Script Tag“ wird zusammengeführt und eine Generic-Rules-RCE-Regel kommt im Block-Modus hinzu.

This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode.

Key Findings

  • Four new detections move from Log to Block: HTTP/2 Request Smuggling - Request Body Anomaly and XSS - JavaScript Event Handler Coercion across Headers, Body, and URI.

  • The XSS, HTML Injection - Script Tag - Beta rule is merged into the original rule.

  • A Generic Rules - Remote Code Execution detection is added in Block mode.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...1489d892

N/A

HTTP/2 Request Smuggling - Request Body Anomaly

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...20646260

N/A

XSS - JavaScript Event Handler Coercion - Headers

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...d706d517

N/A

XSS - JavaScript Event Handler Coercion - Body

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...660886c8

N/A

XSS - JavaScript Event Handler Coercion - URI

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...c293b926

N/A

XSS, HTML Injection - Script Tag - Beta

Log

Block

This rule is merged into the original rule "XSS, HTML Injection - Script Tag" (ID: ...7b58420b).

Cloudflare Managed Ruleset

...2ca6cce3

N/A

Generic Rules - Remote Code Execution

N/A

Block …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF: Leaked-Credentials-Erkennung prüft Authorization-Header

Die Leaked-Credentials-Erkennung prüft nun standardmäßig den Authorization-Header auf Basic-Authentication-Zugangsdaten und gleicht sie mit der Datenbank geleakter Zugangsdaten ab, ohne dass eine Konfiguration nötig ist.

Leaked credentials detection now scans the Authorization request header for Basic Authentication credentials. Previously, the detection only inspected request bodies, query strings, and headers for well-known web applications or custom detection locations, which meant credentials sent through HTTP Basic Authentication were not covered by default.

This new default scan location decodes the Authorization: Basic <credentials> header and compares the extracted username and password against Cloudflare's database of leaked credentials, the same way as other default scan locations. Matches populate the existing leaked credentials fields, such as cf.waf.credential_check.password_leaked, and trigger the Exposed-Credential-Check managed transform header if configured, so you can reuse existing custom rules and rate limiting rules without changes.

This change was applied automatically for zones with leaked credentials detection enabled. No configuration changes are required. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-08-17: WordPress-RCE-Metadaten für CVE-2026-65640

Die Metadaten der WordPress-RCE-Regeln im Managed und Free Ruleset wurden um CVE-2026-65640 ergänzt, wobei Erkennung und Aktionen unverändert bleiben.

This release updates WordPress remote code execution rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify CVE-2026-65640.

Key Findings

  • CVE-2026-65640: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.

Impact

The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...3590a4ad

N/A

Wordpress - Remote Code Execution - CVE:CVE-2026-65640

Block

N/A

Rule metadata description refined. Detection unchanged.

Cloudflare Free Ruleset

...cfe1a93c

N/A

Wordpress - Remote Code Execution - CVE:CVE-2026-65640

Block

N/A

Rule metadata description refined. Detection unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-08-11: vBulletin-RCE CVE-2026-61511

Eine neue Erkennung schützt vor der vBulletin-RCE-Schwachstelle CVE-2026-61511, zudem werden zwei Beta-Regeln (Version Control und vBulletin CVE-2019-17132) in die Originalregeln überführt.

This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections.

Key Findings

  • A new detection provides protection against vBulletin CVE-2026-61511.
  • Two existing detections have been improved to strengthen coverage.

Impact

Successful exploitation of CVE-2026-61511 may lead to remote code execution on affected vBulletin systems, potentially resulting in unauthorized access, data exposure, service disruption, and broader compromise of the hosting environment. Administrators are strongly encouraged to apply vendor updates and recommended mitigations.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...94f3006b

N/A

vBulletin - Remote Code Execution - CVE:CVE-2026-61511

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...098b749e

N/A

Version Control - Information Disclosure - Beta

Log

Block

This rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529)

Cloudflare Managed Ruleset

...d56225d8

N/A

vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132 - Beta

Log

Block

This rule is merged into the original rule "vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132" (ID: ...8fe9f1c7)

Originalquelle(öffnet in neuem Tab)Problem melden