Zum Inhalt springen

Application Security Updates & Release Notes

28 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Application Security, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Turnstile Spin ist jetzt allgemein verfügbar

Turnstile Spin ist allgemein verfügbar und bietet drei Einrichtungswege (Dashboard, Wrangler oder KI-Coding-Agent), um ein Turnstile-Widget zu erstellen und die serverseitige siteverify-Prüfung ins bestehende Backend einzubinden.

Turnstile Spin is now generally available with three setup paths for creating a Turnstile widget and wiring canonical server-side siteverify into your existing backend. Start in the dashboard, with Wrangler, or from your AI coding agent. All three paths create the same widget. You can complete the integration by hand or have your agent embed the widget, wire siteverify, and validate it.

Server-side verification

Turnstile setup has two parts: embed the widget in your frontend, then call siteverify from your backend. Without the second part, the widget appears on the page but does not protect the request.

  • The skill includes insertion snippets for Next.js (App Router and Pages Router), Astro, SvelteKit, Hugo, and vanilla HTML. For other frameworks, the agent proposes a generic pattern and asks you to confirm it first.
  • The Turnstile dashboard flags existing widgets with no matching siteverify traffic. Select Fix with Spin to copy a prompt that guides your agent through wiring siteverify into your backend.
  • Before finishing, the agent runs a real Turnstile token through your protected endpoint, checks that it passes, then replays the token to confirm the endpoint rejects it on the second try. If a check fails, the agent stops and shows you where.

Run Spin

You can run Spin three ways: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-08-07

Die Metadaten der WordPress-XSS-Regeln im Cloudflare Managed und Free Ruleset wurden für XSS2Shell (CVE-2026-64638) angepasst, die Erkennung bleibt unverändert, und die Regel Command Injection - Obfuscation wurde deaktiviert.

This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule.

Key Findings

  • CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen. Exploitation requires social engineering and explicit interaction by the target user. Under additional conditions, it may be escalated to remote code execution.

Impact

The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...9c6dff1c

N/A

Wordpress - XSS - CVE:CVE-2026-64638

Block

N/A

Rule metadata description refined. Detection unchanged.

Cloudflare Free Ruleset

...9ab5ed95

N/A

Wordpress - XSS - CVE:CVE-2026-64638

Block

N/A

Rule metadata description refined. Detection unchanged.

Cloudflare Managed Ruleset

...761e7a4c

N/A

Command Injection - Obfuscation

Block

Disabled

Detection logic has been deprecated

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-08-04

Neue Regel für Microsoft SharePoint RCE (CVE-2026-50522) mit Aktion Block, Umbenennung der Rails-Regel zu CVE-2026-66066 und Entfernung mehrerer Beta-SSRF-Regeln im Zuge verbesserter SSRF-Erkennung für Cloud-Anwendungen.

This release introduces new rules and updates Microsoft SharePoint RCE alongside enhanced SSRF cloud protection rule actions.

Key Findings

  • CVE-2026-50522: An insecure deserialization vulnerability in Microsoft SharePoint Server. This may allow an unauthenticated attacker to execute arbitrary code using crafted requests.
  • CVE-2026-66066: An improper input processing vulnerability in Ruby on Rails Active Storage image variant transformations. This may allow an unauthenticated attacker to perform arbitrary file reads and achieve Remote Code Execution (RCE) using maliciously crafted payload requests.
  • Generic Cloud Protections: Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...052b07cf

N/A

Microsoft SharePoint - Remote Code Execution - CVE:CVE-2026-50522

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...3a5b40d6

N/A

Rails - Arbitrary File Read & RCE - CVE:CVE-2026-66066

Block

Block

This was labeled as File Upload - RCE.

Cloudflare Managed Ruleset

...743a63ec

N/A

SSRF - Local - 2 - Beta

Disabled

-

This detection has been removed.

Cloudflare Managed Ruleset

...c2e84e2d

N/A

SSRF - Cloud - Beta

Disabled

-

This detection has been removed.

Cloudflare Managed Ruleset

...ab8af26f

N/A

SSRF - Cloud - 2 - Beta

Disabled

-

This detection has been removed.…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-07-29

Neue und aktualisierte Regeln schützen vor Schwachstellen in Nuxt Server Islands und Alibaba Fastjson und verbessern zudem die Erkennung von Cloud-Metadata-SSRF und verschleierter Command Injection.

This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Nuxt Server Island components and Alibaba Fastjson deserialization routines, alongside enhanced protections for cloud metadata Server-Side Request Forgery (SSRF) and obfuscated command injection attempts.

Key Findings

  • Nuxt Server Island - RCE(GHSA-9473-5f9j-94wq): An unauthenticated vulnerability in Nuxt Server Islands where remote attackers can supply arbitrary component names or props to endpoints. Manipulating these parameters allows unauthenticated component Remote Code Execution (RCE) on the server.

  • Alibaba Fastjson JSONType Remote Code Execution: A unauthenticated remote code execution vulnerability in Alibaba Fastjson (≤ 1.2.83) during JSON deserialization. Under default configurations, attackers can execute arbitrary system commands, bypassing traditional classpath and gadget-based defenses.

  • Generic Protections (SSRF & Command Injection): Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications, alongside new rules targeting obfuscated command injection patterns across request parameters.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...c2e84e2d

N/A

SSRF - Cloud - Beta

Log

Block

This is an improved detection.

Cloudflare Managed Ruleset

...761e7a4c

N/A

Command Injection - Obfuscation …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-07-21

Neue Regeln decken Schwachstellen in Adobe ColdFusion, Next.js und WordPress ab, darunter CVE-2026-64641 in Next.js, und aktualisierte Regeln verbessern den generischen Schutz vor SSRF, LFI und XSS.

This release introduces new rules for vulnerabilities in Adobe ColdFusion, Next.js, WordPress alongside updates to existing rules thereby providing enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS).

WAF and framework adapter mitigations for Next.js vulnerabilities

Multiple security vulnerabilities ↗︎ were disclosed and patched by the Next.js team through July 2026 security release. These include denial of service, middleware and proxy bypass, server-side request forgery, information disclosure, and cache poisoning across a range of severities.

Several of the disclosed vulnerabilities are not possible to block at WAF layer,we strongly recommend updating your application and its dependencies immediately. Patched versions are available through v16.2.11 (Active LTS) and v15.5.21 (Maintenance LTS) to address these issues.

Advisory

CVE

Severity

Issue

WAF Coverage

Denial of Service in App Router using Server Actions

CVE-2026-64641

High

Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage. The CPU usage blocks processing of further requests in the same process, leading to Denial of Service.

WAF rule Next.js - DoS - CVE-2026-64641 (...90dcdb0a) has been deployed to provide coverage. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Notfall-Release 2026-07-17

Neue Managed-Regeln im Cloudflare Managed und Free Ruleset blockieren aktiv ausgenutzte unauthentifizierte RCE- und SQL-Injection-Schwachstellen in verbreiteten Web-Frameworks.

This emergency release adds a new managed rule to block active exploitation of a critical remote code execution (RCE) and SQL injection (SQLi) vulnerability found in popular web frameworks.

Key Findings

  • Generic Frameworks - Unauthenticated RCE: Attackers can execute arbitrary system commands with web server privileges by sending malicious input containing invalid path sequences during request processing.

  • Generic Frameworks - SQLi: Attackers can execute unauthorized database queries due to a failure to sanitize input values within request parameters.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...550664b6

N/A

Generic Rules - Unauthenticated RCE

N/A

Block

This is a new detection.

Cloudflare Managed Ruleset

...ed933fcc

N/A

Generic Rules - SQLi

N/A

Block

This is a new detection.

Cloudflare Free Ruleset

...b5ec246a

N/A

Generic Rules - Unauthenticated RCE

N/A

Block

This is a new detection.

Cloudflare Free Ruleset

...33697a1a

N/A

Generic Rules - SQLi

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-07-14

Neue Regeln blockieren Angriffe auf Citrix NetScaler ADC und Gateway (CVE-2026-8451) sowie auf Progress Kemp LoadMaster (CVE-2026-8037).

This release introduces new rules targeting critical infrastructure vulnerabilities. These include an unauthenticated memory disclosure flaw in Citrix NetScaler ADC and Gateway (CVE-2026-8451) and a high-severity pre-authentication remote code execution (RCE) vulnerability in Progress Kemp LoadMaster (CVE-2026-8037).

Key Findings

  • CVE-2026-8451: An insufficient input validation vulnerability affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML Identity Provider (IdP). Remote, unauthenticated attackers can exploit this flaw by sending malformed requests to trigger a memory overread, allowing them to leak chunks of sensitive data from adjacent appliance memory.

  • CVE-2026-8037: A critical OS command injection vulnerability in Progress Kemp LoadMaster load balancers allows unauthenticated remote attackers to achieve remote code execution (RCE).

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...76973ac4

N/A

Citrix Netscaler ADC - Insufficient Input Validation - CVE:CVE-2026-8451

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...10233f36

N/A

Progress Kemp LoadMaster - Remote Code Execution - CVE:CVE-2026-8037

Log

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Precursor: sitzungsbasierte Bot-Erkennung

Precursor, ein clientseitiges JavaScript für sitzungsbasierte Bot-Erkennung, wird ab heute für alle Kunden ausgerollt und lässt sich im Cloudflare-Dashboard mit konfigurierbaren Modi aktivieren.

Precursor is rolling out to all customers starting today. Precursor is client-side JavaScript that enables session-based bot detection.

You can read the announcement blog ↗︎ for background on why we built Precursor and how session-level behavioral detection works.

With Precursor enabled, Cloudflare can:

  • Continuously evaluate behavioral signals across a session
  • Re-validate challenge clearance as behavior changes
  • Update bot scores with session context
  • Provide client-side visibility where none previously existed

It integrates with existing protections, including Security Rules, and can be enabled directly from the Cloudflare dashboard with configurable modes to balance security and user experience.

Animated walkthrough of enabling Precursor in the Cloudflare dashboard

To learn more, refer to the Precursor documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security Updates & Release Notes (Cloudflare) – Oktober 2026 (Seite 2) | updatefeed