Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.8.1755.1 (Beta)

Das Beta-Release 2026.8.1755.1 des Cloudflare One Client für Windows bringt Fehlerbehebungen und Verbesserungen, etwa bei Reauthentifizierung, MTU-Handling, DNS-Zuverlässigkeit und Dienstwiederherstellung.

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Fixed an issue that could briefly block traffic to split tunnel excluded resources while the client was connecting or reconnecting.
  • Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
  • Improved client reaction to the current network lowering its MTU.
  • Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • The client no longer requires the Windows WLAN AutoConfig service to be running.
  • Implemented a service recovery mechanism backed by Windows scheduler task to start WARP service on system unlock if not already started.
  • Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
  • Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Unified Routing jetzt allgemein verfügbar

Unified Routing ist für Cloudflare WAN und Magic Transit allgemein verfügbar, bietet unter anderem Automatic Return Routing, BGP und benutzerdefinierte Client-Subnetze und wird für alle neuen Konten empfohlen.

Unified Routing is generally available for Cloudflare WAN and Magic Transit.

Unified Routing improves the integration between Cloudflare One and the standard connectivity onramps supported by Cloudflare WAN. It is capable of many new features including Automatic Return Routing, BGP and custom client subnets.

We recommend Unified Routing for all new accounts.

For details, refer to Cloudflare WAN traffic steering and Magic Transit traffic steering.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access for Infrastructure unterstützt Tags für Targets und tagbasierte Kriterien

Access for Infrastructure unterstützt jetzt Resource Tagging, sodass Targets mit Schlüssel-Wert-Tags versehen und in Richtlinien über Target-Kriterien mit include, require und exclude nach Hostname oder Tag ausgewählt werden können.

Access for Infrastructure now integrates with Resource Tagging. You can attach key-value tags to infrastructure targets and use them in access policies.

You can manage tags on targets inline when you create or edit a target or through the central Resource Tagging API. Cloudflare keeps tags in sync across both methods.

Infrastructure applications also support a target criteria model with include, require, and exclude operators. Each operator can match targets by hostname, tag, or both.

  • Include matches targets that have any of the specified values.
  • Require matches targets that have all of the specified values.
  • Exclude rejects targets that have any of the specified values.

Infrastructure application builder showing target criteria with an included tag, port 22, and SSH as the selected protocol …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Frische Authentifizierung für SAML-Identity-Provider erzwingen

Cloudflare Access kann bei SAML-Identity-Providern für jeden Login eine frische Authentifizierung anfordern, indem „Require reauthentication“ aktiviert oder „force_authn“ auf true gesetzt wird.

Cloudflare Access can now request fresh authentication from a SAML identity provider for every login. Turn on Require reauthentication in the Cloudflare dashboard, or set force_authn to true through the API. Access will then set ForceAuthn to true in signed and unsigned SAML authentication requests.

This option is useful when an application requires users to reauthenticate at the identity provider instead of relying on an existing identity provider session. The default value is false.

For configuration details, refer to Require fresh authentication at the identity provider.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Passive Detection zeigt, wohin sensible Daten fließen

Passive Detection für Cloudflare DLP ist allgemein verfügbar und zeigt in einem Dashboard sensible Datentypen und deren Ziele aus gesampelten Gateway-Traffic-Daten, ohne dass eine Gateway-DLP-Policy nötig ist.

Passive Detection for Cloudflare Data Loss Prevention (DLP) lets you learn from your Gateway traffic before deciding what to log or block. Discover the sensitive data types in sampled traffic, explore their destinations, and use the findings to build policies around your organization's needs.

The dashboard brings together detections from sampled HTTP request and response bodies. Select an entry to follow its detections over time, review destinations, and check policy coverage. You do not need a Gateway DLP policy to get these insights, and existing Gateway policies continue to apply.

Passive Detection dashboard showing detection totals, data type distribution, policy coverage, and detection entries

Passive Detection is generally available. The detection entries available to your account depend on your Zero Trust plan.

To get started, refer to the Passive Detection documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.8.1290.1 (Beta)

Das Beta-Release 2026.8.1290.1 des Cloudflare One Client für macOS unterstützt das Routing nicht-RFC-1918-konformer lokaler IPv4-Netze durch den WARP-Tunnel und verbessert die DNS- und API-Zuverlässigkeit, außerdem behebt es mehrere Fehler.

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • Fixed Extra Logging failing to capture packets across all interfaces.
  • Fixed an issue that could prevent remote diagnostics from completing.
  • Fixed DNS connectivity checks failing on IPv6-only networks.
  • Fixed the client service exiting when its route-monitoring socket was closed after sleep or wake.
  • Fixed DNS enforcement checks making the client service unresponsive on systems with large routing tables.
  • Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
  • Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
  • Fixed the client continuing to report 'No network' after a successful manual disconnect. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.8.1290.1 (Beta)

Das Beta-Release 2026.8.1290.1 des Cloudflare One Client für Windows unterstützt das Routing nicht-RFC-1918-konformer lokaler IPv4-Netze, benötigt den Windows-Dienst WLAN AutoConfig nicht mehr und behebt mehrere Fehler, etwa bei DEX-HTTP-Tests und beim Start der Client-Oberfläche.

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • The client no longer requires the Windows WLAN AutoConfig service to be running.
  • Implemented a service recovery mechanism backed by Windows scheduler task to start WARP service on system unlock if not already started.
  • Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
  • Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
  • Fixed the client continuing to report 'No network' after a successful manual disconnect.
  • Fixed Digital Experience Monitoring (DEX) HTTP tests failing TLS validation on Windows.
  • Fixed the client UI crashing at startup when it could not write to the Windows registry. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Browser Isolation: Verbesserte Tap-to-type-Eingabe unter iOS

Browser Isolation zeigt die Tap-to-type-Aufforderung auf iOS-Geräten jetzt inline über dem fokussierten Textfeld statt als Vollbild-Overlay, bei sehr kleinen Feldern erscheint stattdessen ein Tastatursymbol.

Browser Isolation has improved the tap-to-type experience for users on iOS devices.

Previously, Browser Isolation displayed a full-screen overlay with the message tap to type when users focused a text field. The prompt now appears inline over the focused text field, reducing disruption when users enter text in isolated sessions.

If the focused text field is too small to display the full prompt, Browser Isolation displays a keyboard icon in the center of the text field instead.

Inline tap-to-type prompt over a focused text field in Browser Isolation

iOS users should tap twice to begin entering text. This update applies automatically to Browser Isolation sessions on iOS.

For more information on why this interaction is required, refer to iOS limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Neue Integration für Zoom

Cloudflare CASB lässt sich jetzt per vorgefertigter OAuth-Anwendung mit Zoom integrieren und scannt Kontoeinstellungen, Benutzerkonten und Meetings fortlaufend auf Sicherheitsbefunde.

Cloudflare CASB now integrates with Zoom. The integration connects through Cloudflare's pre-built OAuth application — no manual app setup in Zoom is required. After an initial scan, CASB continuously scans your Zoom account to surface new findings as your environment changes.

Zoom is widely used for meetings, webinars, and collaboration. Misconfigurations in account settings, meeting security controls, and recording access can expose organizations to data leakage, unauthorized access, and compliance risk. Cloudflare CASB ingests Zoom account data via API to surface security findings across these areas.

Key capabilities

Starting today, security teams can scan for security findings across the following assets:

  • Account settings — Detect weak password policies, unlocked security controls, and two-factor authentication gaps across your Zoom account
  • User accounts — Identify users not enforcing SSO, accounts with insecure host keys, unverified or inactive users, and unsafe overrides of account-level security settings
  • Meetings — Surface meetings without passwords or waiting rooms, meetings using Personal Meeting IDs (PMIs), and meetings with external domain hosts …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Appliance: Eigene Anwendungen im Dashboard definieren

Benutzerdefinierte Anwendungen für Breakout- und priorisierten Traffic lassen sich auf der Cloudflare One Appliance jetzt direkt im Dashboard anlegen, bearbeiten und löschen, ohne die API zu nutzen.

You can now define custom applications for breakout and prioritized traffic on the Cloudflare One Appliance directly from the dashboard, without calling the API.

Adding a custom application by hostname, IP subnet, and source subnet from the Traffic Steering tab of an appliance profile

  • In Traffic Steering > Breakout traffic or Prioritized traffic, select Assign application traffic > Add to create a custom application matched by Hostnames, IP subnets, and/or the new Source subnets field, alongside Cloudflare-managed applications.
  • Edit or delete an existing custom application from the same panel, no API round-trip required. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Appliance: DHCP-Optionen im Dashboard konfigurieren

Benutzerdefinierte DHCP-Optionen können jetzt direkt im Dashboard konfiguriert werden, wenn die Cloudflare One Appliance als DHCP-Server für ein LAN dient.

You can now configure custom DHCP options directly from the dashboard when the Cloudflare One Appliance is acting as the DHCP server for a LAN.

Adding a custom DHCP option to a LAN's DHCP server from the Network Configuration tab of an appliance profile

  • In LAN configuration, under DHCP server options, select Add DHCP option to choose from common options for PXE / iPXE boot, VoIP phone provisioning, and vendor-specific configuration, or select Add custom option to enter your own option code, type, and value.
  • This complements the existing API and Terraform workflow for configuring DHCP options.

For details, refer to DHCP server options.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Mehrere Cloudflare Tunnel- und Cloudflare Mesh-Routen gleichzeitig anlegen

Auf der Routes-Seite lassen sich mehrere Cloudflare Tunnel- und Cloudflare Mesh-Routen in einer einzigen Aktion anlegen, wobei bei Fehlern nur die fehlgeschlagenen Routen erneut übermittelt werden müssen.

You can now create multiple Cloudflare Tunnel and Cloudflare Mesh routes from the Routes page in a single action, instead of submitting one route at a time.

Creating multiple Cloudflare Tunnel and Cloudflare Mesh routes at once from the Routes page

When creating a route, you can now:

  • Add multiple destinations at once — Enter a comma-separated list of CIDR ranges or hostnames to create several routes of the same type and connector together.
  • Queue up multiple routes — Select Add another to stage additional routes, including different types or connectors, before creating them all in one action.
  • Retry only what failed — If some routes in a batch fail (for example, an invalid CIDR), the routes that were created successfully are removed from the form automatically, so you only need to fix and resubmit the ones that failed.

The same Routes UI already supports bulk creation for Cloudflare WAN static routes, so you can add multiple WAN destinations or queue up several WAN routes before creating them together as well.

Go to Routes ↗ …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.7.1376.0

Der Cloudflare One Client für macOS 2026.7.1376.0 ist als GA-Hotfix verfügbar und behebt ein Problem, bei dem ein kleiner, aber spürbarer Anteil der DNS-Anfragen fehlschlug.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.7.1376.0

Der Cloudflare One Client für Windows 2026.7.1376.0 ist als GA-Hotfix verfügbar und behebt fehlschlagende DNS-Anfragen sowie ein seltenes Problem, bei dem nach einem Versionswechsel Verbindung oder Organisationswechsel an einer ungültigen Registrierung scheitern konnten.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

Fixed a rare but critical issue where the client could fail to connect or switch organizations due to an invalid registration after switching installed client versions. Additionally, this hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.7.1377.0

Der Cloudflare One Client für Linux 2026.7.1377.0 ist als GA-Hotfix verfügbar und behebt ein Problem, bei dem ein kleiner, aber spürbarer Anteil der DNS-Anfragen fehlschlug.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Service-Token-Secrets in scanbarem Format

Cloudflare Access Service-Token-Client-Secrets, die ab dem 26. August 2026 erstellt werden, verwenden das Format cfast_ mit Präfix und Prüfsumme, damit Secret-Scanning-Tools sie leichter erkennen, während bestehende Secrets weiter funktionieren.

Cloudflare Access service token Client Secrets created on or after August 26, 2026, use the format cfast_[40 alphanumeric characters][8-character checksum]. The prefix and checksum make these credentials easier for secret scanning tools to identify with fewer false positives.

Existing service token secrets continue to work and do not require rotation. Both formats use the same Client ID and the same CF-Access-Client-Id and CF-Access-Client-Secret authentication headers.

For more information, refer to Service tokens.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Übergangsfristen bei der Rotation von Service Tokens

Administratoren können bei der Rotation eines Access-Service-Token-Secrets nun eine Übergangsfrist von einer Stunde bis 30 Tagen wählen, in der beide Secrets gültig bleiben.

Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication.

The dashboard offers grace periods from one hour to 30 days. Administrators can also revoke the previous secret immediately. The API accepts an RFC 3339 expiration time for custom rotation schedules.

For configuration instructions, refer to Rotate service token secrets.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Service Tokens vorübergehend deaktivieren

Access-Administratoren können Service Tokens jetzt vorübergehend deaktivieren, ohne sie zu löschen, sodass ein deaktiviertes Token sich nicht authentifizieren kann, seine Konfiguration aber erhalten bleibt.

Cloudflare Access administrators can now temporarily turn off service tokens without deleting them. A disabled token cannot authenticate, but its configuration remains available so administrators can turn it on again later.

Turning off a token also stops any previous secret in an active rotation grace period. Use this control to contain suspected credential exposure or pause an automated service.

For configuration instructions, refer to Turn a service token on or off.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

MCP-Server-Portale unterstützen MCP-Spezifikation 2026-07-28

MCP server portals unterstützen die zustandslose MCP-Spezifikation 2026-07-28 für Client- und Upstream-Verbindungen und greifen bei Bedarf automatisch auf den 2025-Handshake zurück.

MCP server portals support the stateless MCP 2026-07-28 specification for client and upstream server connections.

The portal's /mcp endpoint automatically accepts stateless MCP 2026-07-28 requests and earlier 2025 Streamable HTTP clients. When the portal connects to an upstream Streamable HTTP server, it checks for MCP 2026-07-28 support and falls back to the 2025 handshake when needed. Client and upstream protocol selection are independent, so clients and servers can upgrade separately without portal configuration changes.

SSE connections continue to use the legacy protocol. For details, refer to MCP server portal transport and protocol compatibility.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Virtual Appliance je Hypervisor im Dashboard herunterladen

Beim Registrieren einer Cloudflare One Virtual Appliance lässt sich im Dashboard jetzt der Hypervisor (VMware ESXi, Proxmox oder libvirt/KVM) auswählen und das passende OVA-Image oder Installationsskript direkt herunterladen.

When you register a Cloudflare One Virtual Appliance, you can now select your hypervisor and download the appliance directly from the dashboard — no need to look up asset URLs.

Selecting a hypervisor and downloading the Cloudflare One Virtual Appliance from the Connectors page

  • On the Connectors page, select Add an appliance, choose Virtual appliance, then select your hypervisor: VMware ESXi, Proxmox, or libvirt/KVM.
  • Download the OVA image (VMware ESXi) or the install script (Proxmox and libvirt/KVM) for the selected hypervisor.
  • Use View setup guide to open deployment instructions for your platform.

This complements the existing self-serve registration and license key generation in the dashboard.

For details, refer to Configure a Cloudflare One Virtual Appliance.

Originalquelle(öffnet in neuem Tab)Problem melden