Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Autorisierungs-Cookies für Access-Anwendungen mit mehreren Domains steuern

Administratoren können bei selbst gehosteten Access-Anwendungen mit der neuen Einstellung „Eager redirect cookie“ steuern, ob Autorisierungs-Cookies vorab für alle Hostnamen gesetzt werden, unabhängig von deren Anzahl.

Cloudflare Access administrators can now control whether a self-hosted application preemptively sets authorization cookies across its public hostnames.

Previously, Access automatically used eager redirects for applications with five or fewer hostnames. Applications with more than five hostnames received cookies as users visited each hostname. Administrators can now choose either behavior, regardless of the number of hostnames.

The new Eager redirect cookie setting is turned on by default for new applications. After a user signs in, Access redirects the browser through each hostname and sets a CF_Authorization cookie. This supports applications that need to make requests across hostnames before the user visits each one.

For applications with many hostnames, the redirect chain can cause sign-in loops in some browsers. Turn off the setting to issue the cookie only when a user visits each hostname.

To configure the setting, refer to Authorization cookie.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.7.1210.1 (Beta)

Das Beta-Release 2026.7.1210.1 des Cloudflare One Client für Windows verbessert die Verbindungszuverlässigkeit durch Protokollwechsel bei blockiertem HTTP/3 und behebt mehrere Fehler, darunter MASQUE-Stalls und den Organisationswechsel.

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Improved connection reliability: the client now swaps protocol order after repeated connectivity-check failures, which helps when HTTP/3 is blocked after the QUIC handshake.
  • Fixed issue where a certificate error could be incorrectly displayed right after the connection is established.
  • A DNS search domain parsing failure no longer prevents connection.
  • Fixed a MASQUE issue where the tunnel could stall while uploading at a high rate.
  • Fixed being unable to switch organizations when the client was stuck in the "Device not in organization" state.
  • Fixed the Home Screen dropdown popup not anchoring correctly.
  • Fixed a crash during dialog dismissal. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.7.1210.1 (Beta)

Das Beta-Release 2026.7.1210.1 des Cloudflare One Client für macOS verbessert die Verbindungszuverlässigkeit durch Protokollwechsel bei blockiertem HTTP/3 und behebt mehrere Fehler, darunter MASQUE-Stalls und den Organisationswechsel.

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Improved connection reliability: the client now swaps protocol order after repeated connectivity-check failures, which helps when HTTP/3 is blocked after the QUIC handshake.
  • Fixed issue where a certificate error could be incorrectly displayed right after the connection is established.
  • A DNS search domain parsing failure no longer prevents connection.
  • Fixed a MASQUE issue where the tunnel could stall while uploading at a high rate.
  • Fixed being unable to switch organizations when the client was stuck in the "Device not in organization" state.
  • Fixed the Home Screen dropdown popup not anchoring correctly.
  • Fixed a crash during dialog dismissal. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Statische OAuth-Client-Zugangsdaten für MCP server portals

MCP server portals können sich nun mit vorab registrierten statischen OAuth-Client-Zugangsdaten (Client-ID und -Secret) mit Upstream-MCP-Servern verbinden, die keine Dynamic Client Registration unterstützen.

MCP server portals can now connect to upstream MCP servers that require a pre-registered OAuth client. This supports OAuth providers that do not offer Dynamic Client Registration or have disabled it. This unlocks portal connections to major SaaS providers such as Slack and GitHub, whose MCP servers do not yet support DCR.

When adding an MCP server, administrators can enter the client ID and client secret from an OAuth application registered with the upstream provider. The configuration also supports custom OAuth endpoints, scopes, and the client_secret_post and client_secret_basic token endpoint authentication methods.

Cloudflare stores the client secret encrypted. Users still authenticate to the upstream server with their own accounts when they connect through a portal.

For setup instructions, refer to Configure manual OAuth credentials.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Code Mode für MCP-Portal-Nutzer standardmäßig aktivierbar

Admins können für MCP server portals nun vier Code-Mode-Richtlinien (Off, Opt-in, On by default, Enforced) festlegen, die über das neue API-Feld code_mode gesteuert werden, während das bisherige Boolean allow_code_mode veraltet ist.

MCP server portals now support four Code Mode policies: Off, Opt-in, On by default, and Enforced. Admins can choose whether Code Mode is unavailable, optional, enabled by default, or required for every session.

Existing portals retain their current behavior. Portals that previously allowed Code Mode use Opt-in, while portals that did not allow Code Mode use Off. New portals also use Opt-in by default.

Clients turn on Code Mode for an Opt-in portal with ?codemode=search_and_execute. The On by default policy lets clients opt out with ?codemode=off, which avoids nested code execution when a client runs its own Code Mode implementation. The Off and Enforced policies ignore client overrides.

The Cloudflare API exposes these policies through the code_mode field:

{
	"code_mode": "default_on"
}

The supported values are off, opt_in, default_on, and enforced. The previous allow_code_mode boolean is deprecated.

For configuration details and client behavior, refer to Code Mode policies.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway: DNS-Caching per maximaler TTL steuern

Gateway kann DNS-Antworten nun auf eine konfigurierbare maximale TTL (60 bis 36.000 Sekunden) begrenzen, auf Account- oder DNS-Location-Ebene, und protokolliert dazu die neuen DNS-Log-Felder upstream_record_ttls und applied_max_ttl.

You can now set a maximum time-to-live (TTL) for DNS responses returned by Gateway. When an upstream DNS record has a TTL that exceeds the configured maximum, Gateway caps it to your specified value. This ensures that DNS policy changes - such as blocking a newly identified malicious domain - take effect faster across all clients.

The maximum DNS TTL setting in Traffic policies > Traffic settings, showing a numeric input field that accepts values between 60 and 36,000 seconds

The setting is available at two levels:

  • Account level - In Traffic Policies > Traffic Settings, under Proxy and inspection. This sets the default cap for all DNS locations.
  • Per-location - Each DNS location can inherit the account setting, disable the cap, or override it with a custom value.

Two new fields are also available in DNS logs: upstream_record_ttls (the original TTL from the upstream response) and applied_max_ttl (the cap Gateway applied). These appear in the DNS logs column picker and in Logpush datasets.

For more information, refer to Maximum DNS TTL.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.6.880.0

Der Cloudflare One Client für Windows 2026.6.880.0 behebt eine Regression mit stark erhöhten DNS-over-TCP-Anfragen, indem Fallback-DNS-Anfragen zuerst per UDP und nur bei gekürzter Antwort per TCP gesendet werden.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.6.880.0

Der Cloudflare One Client für macOS 2026.6.880.0 behebt eine Regression mit stark erhöhten DNS-over-TCP-Anfragen, indem Fallback-DNS-Anfragen zuerst per UDP und nur bei gekürzter Antwort per TCP gesendet werden.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.6.880.0

Der Cloudflare One Client für Linux 2026.6.880.0 behebt eine Regression mit stark erhöhten DNS-over-TCP-Anfragen, indem Fallback-DNS-Anfragen zuerst per UDP und nur bei gekürzter Antwort per TCP gesendet werden.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Browserbasierter Login für private HTTP-Anwendungen in Access

Private Anwendungen über unverschlüsseltes HTTP auf Port 80 nutzen in Cloudflare Access nun den standardmäßigen browserbasierten Login statt des Pop-up-Ablaufs des Cloudflare One Client, ohne dass eine Konfigurationsänderung nötig ist.

Cloudflare Access now uses the standard browser-based login flow for private applications served over plaintext HTTP on port 80.

Previously, plaintext HTTP private apps fell back to the same session flow used for SSH, RDP, and other non-HTTP protocols: users got an Authentication required pop-up from the Cloudflare One Client, then had to select the notification to open a browser and log in. Now, users hitting an HTTP private app see the Access login page directly in the browser and receive a standard Access application token on success.

This brings the HTTP experience in line with HTTPS apps (with Gateway TLS decryption turned on). No configuration change is required. The Cloudflare One Client is still required to route traffic to the private network, but it no longer manages the Access session for HTTP apps.

Other non-HTTP protocols (SSH, RDP, arbitrary TCP/UDP) continue to use the Cloudflare One Client notification flow.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Appliance per Dashboard neu starten oder herunterfahren

Eine Cloudflare One Appliance lässt sich nun per Dashboard oder API neu starten (Restart), rebooten oder herunterfahren.

You can now restart, reboot, or shut down a Cloudflare One Appliance directly from the dashboard or via API.

Restarting a Cloudflare One Appliance from the Operations section of the Edit Appliance page

  • Restart — Restart managed services. Purges temporary and (optionally) persistent state.
  • Reboot — Power cycle the appliance. Optionally, purge persistent state. Re-applies configuration starting from scratch.
  • Shutdown — Power off the appliance. Optionally, purge persistent state. The machine will be offline until manually powered on again.

In the dashboard, go to Networking > Connectors > Appliances, select an appliance, then Edit > Operations to send an operation. Via API, POST to the /accounts/{account_id}/magic/connectors/{connector_id}/interrupts endpoint.

For details, refer to Appliance operations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Header-Optionen für Gateway-HTTP-Richtlinien

Gateway-HTTP-Allow-Richtlinien können nun Header von passenden Anfragen hinzufügen, überschreiben oder löschen und dabei statische Werte oder dynamische Variablen mit @{...}-Syntax verwenden.

Cloudflare Gateway now supports advanced header control on Allow policies. Administrators can add, overwrite, or delete headers on matching requests using static values or dynamic variables.

Header operations

Gateway HTTP policies using the Allow action support three operations in rule_settings:

Operation

API field

Behavior

Add

add_headers

Appends a value to the header. Existing values are preserved.

Overwrite

set_headers

Replaces the header value. Creates the header if it does not exist.

Delete

delete_headers

Removes the header from the request.

Gateway applies operations in order: delete, then overwrite, then add.

Dynamic variables

Header values can include dynamic variables using the @{...} syntax. Gateway resolves variables at request time from identity, device, and network context.

Variable

Description

@{identity.email}

User email from the identity provider

@{identity.name}

User display name from the identity provider

@{identity.id}

Cloudflare identity UUID

@{identity.groups}

Identity provider group memberships

@{identity.SAML}

SAML attributes (if configured)

@{identity.OIDC}

OIDC claims (if configured)

@{source.ip}

Source IP of the connection

@{destination.ip}

Destination IP of the request

@{device.id}

Cloudflare One Client device UUID

@{device.posture} …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Mehrere PDFs in browserbasiertem RDP gesammelt drucken

In browserbasierten RDP-Sitzungen lassen sich mehrere PDF-Dateien über „Print all PDFs“ im Zwischenablage-Panel als ein einziger Druckauftrag an den lokalen Drucker senden, in Chromium-basierten Browsern und Firefox.

Users in browser-based RDP sessions can now print multiple PDF files as a single print job. Copy the files to your clipboard on the remote machine, then select Print all PDFs in the clipboard panel. The files are combined into one PDF and sent to your local printer.

The clipboard panel showing the Print all PDFs option for multiple selected PDF files.

Bulk print is available in Chromium-based browsers and Firefox. For more information, refer to Print PDFs for browser-based RDP.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Internal DNS ist jetzt allgemein verfügbar

Internal DNS ist allgemein verfügbar und bietet autoritatives und rekursives DNS für private Netzwerke auf derselben Plattform wie öffentliches DNS, mit Views für Split-Horizon-DNS und Resolver-Richtlinien über Gateway.

Internal DNS is now generally available. Internal DNS provides authoritative and recursive DNS for private networks on the same global network and control plane you already use for public DNS, Zero Trust, and application services.

Why it matters

  • Consolidate DNS operations. Public and private DNS run on one platform, with one API, one audit trail, and one place to set policy.
  • Simplify split-horizon DNS. Internal and external resolution are defined as separate views over shared zones, managed from a single control plane — so there is no drift to chase down.
  • Extend Zero Trust to DNS. Resolver policies decide which users and devices resolve against which view, enforced by the same Gateway that already governs the rest of your traffic.

Setting up Internal DNS takes three steps: create a zone, create a view, and define a resolver policy.

POST /zones
{
  "account": {
    "id": "<ACCOUNT_ID>"
  },
  "name": "corp.internal",
  "type": "internal"
}

Internal DNS is included with Cloudflare Gateway for Enterprise customers. To get started, refer to the Internal DNS documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Verbesserte Erkennung von Quellcode

Die DLP-Quellcode-Erkennung bewertet nun nur noch vollständige Quellcode-Dateien mit mindestens 500 Zeichen, wodurch eingebetteter Code etwa in Chats oder Dokumentation nicht mehr fälschlich erkannt wird.

Data Loss Prevention (DLP) source code detection now focuses on identifying whole source code file uploads and downloads. Previously, source code detection performed partial scans resulting in a higher rate of false positives. Since only whole source code files are evaluated, code embedded in other content — such as chat messages, documentation, or code samples — is no longer flagged as source code, removing a common source of false positives.

Source code detection requires a minimum of 500 characters to evaluate a file. Files below this threshold are not flagged to reduce noise. This threshold filters out small fragments that lack enough context for reliable classification.

Enable and set confidence levels to tune match sensitivity. A higher confidence level reduces false positives by requiring stronger signals that the content is truly source code. A lower confidence level catches more files at the cost of additional noise.

Source code detection applies to standalone source code files in Gateway HTTP policies. It does not detect source code embedded within other file types or payloads, such as .docx files or chat messages. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WLAN-Signal und Netzwerkanalysen für Geräte in Digital Experience Monitoring

Die Seite Device Monitoring in Digital Experience Monitoring analysiert nun Hardware- und Netzwerkdaten von Cloudflare One Client Geräten und zeigt Verbindung, WLAN-Signalstärke, Datenverkehrsleistung und Gerätezustand mit Bewertungen von Good, Fair und Poor.

Digital Experience Monitoring (DEX) provides visibility into device, network, and application performance across your Cloudflare SASE deployment.

The Device Monitoring page now analyzes hardware and network data between a Cloudflare One Client device and Cloudflare's edge, so you can diagnose connectivity and performance issues. Previously, this data was only available in raw DEX Device State Event logs, which required you to build your own analytics to interpret it.

Device Monitoring summary with connection status, connection mode, Wi-Fi signal strength, traffic performance, and device health

A summary at the top of the page shows the health of each category at a glance, using Good, Fair, and Poor labels:

  • Connection — connection status, Cloudflare One Client mode, and tunnel type over time
  • Wi-Fi signal strength — signal measured in dBm over time, with thresholds that flag a weak signal
  • Traffic performance — upstream and downstream performance, including network throughput on the active interface
  • Device health — hardware metrics such as CPU, memory, and disk …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Zero-Trust-Networks-Route-Endpunkte und Feld connections entfallen am 5. Oktober 2026

Am 5. Oktober 2026 werden die CIDR-kodierten Route-Endpunkte der Zero Trust Networks API entfernt und das Feld connections entfällt aus den Tunnel-Antworten, weshalb Nutzer vorher auf die route_id-basierten Endpunkte migrieren müssen.

On October 5, 2026, two changes take effect across the Zero Trust Networks API and Cloudflare Tunnel API: the CIDR-encoded route endpoints are removed, and tunnel list and get responses no longer include the connections field. If you manage private network routes or read tunnel connection details through the API, cloudflared, Terraform, or another integration, review the changes in the following sections and migrate before the removal date.

Route endpoints

The CIDR-encoded route endpoints are deprecated in favor of the standard, route_id-based endpoints that already exist today. Both sets of endpoints route a private network through Cloudflare Tunnel or Cloudflare Mesh (the API still refers to Mesh nodes as warp_connector) — only the request shape changes.

Deprecated endpoints (removed October 5, 2026):

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

IPsec-Downgrade-Schutz (Beta)

Cloudflare IPsec unterstützt in der Beta die IKEv2-Erweiterung IKE_SA_INIT_FULL_TRANSCRIPT_AUTH als Schutz vor Downgrade-Angriffen auf IPsec-Tunnel, die per Feature-Flag über das Account-Team aktiviert wird.

Cloudflare IPsec now supports the IKE_SA_INIT_FULL_TRANSCRIPT_AUTH ↗︎ IKEv2 extension to protect against downgrade attacks on IPsec tunnels.

IKEv2's original authentication design has each endpoint sign only its own outbound messages, not the full handshake transcript. A quantum-capable on-path attacker ↗︎ can exploit this to bypass post-quantum key exchange by downgrading the connection to classical cryptography. The IKE_SA_INIT_FULL_TRANSCRIPT_AUTH extension addresses this by having both peers sign the entire handshake transcript during the authentication exchange, preventing an attacker from manipulating the negotiation without detection.

Key details:

  • Available in beta for Cloudflare WAN and Magic Transit IPsec tunnels.
  • Cloudflare sends the IKE_SA_INIT_FULL_TRANSCRIPT_AUTH notification unconditionally as a responder when the feature flag is enabled.
  • Both the initiator (your device) and responder (Cloudflare) must support the extension for downgrade protection to be effective.
  • This feature is currently gated by a per-account feature flag. Contact your account team to turn it on.

Refer to Downgrade protection for more details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

IP-Listen, IDS- und SIP-Regeln jetzt in Unified Routing unterstützt

Cloudflare Advanced Network Firewall unterstützt IP-Listen, IDS- und SIP-Regeln nun auch für Accounts im Unified-Routing-Modus, wofür ein Abonnement von Cloudflare Advanced Network Firewall nötig ist.

Cloudflare Advanced Network Firewall IP lists, IDS, and SIP rules are now supported for accounts using Unified Routing mode. These features require a Cloudflare Advanced Network Firewall subscription.

Support for additional features - Threat Intel Lists, Rate Limiting, and Managed Rulesets - is planned.

For the full list of current beta limitations, refer to Traffic steering beta limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.6.850.0

Der Cloudflare One Client für Windows 2026.6.850.0 behebt ein Authentifizierungsproblem im eingebetteten WebView2-Browser, sodass SSO-Anbieter das primäre Windows-Konto wieder nutzen können.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This hotfix addresses a Windows authentication issue in the embedded WebView2 browser. Single sign-on could fail to use the Windows primary account, causing users to be prompted for an interactive sign-in. The embedded authentication browser now allows SSO providers to use the OS primary account when available.

Originalquelle(öffnet in neuem Tab)Problem melden