Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Dateiübertragungskontrollen für browserbasiertes RDP (Beta)

Für browserbasiertes RDP mit Cloudflare Access lassen sich in der Beta pro Richtlinie Dateiübertragungen zwischen lokalem Rechner und Remote-Windows-Server in eine oder beide Richtungen erlauben oder einschränken.

You can now configure file transfer controls for browser-based RDP with Cloudflare Access, allowing you to restrict whether users can upload or download files between their local machine and the remote Windows server.

File transfer connection settings in the Access policy configuration.

This feature is useful for organizations that support bring-your-own-device (BYOD) policies or third-party contractors using unmanaged devices. By restricting file transfers, you can prevent sensitive data from being moved out of the remote session to a user's personal device.

Configuration options

File transfer controls are configured per policy within your Access application, alongside existing text clipboard controls. For each policy, you can select one of the following options:

  • Client to remote RDP session allowed — Users can upload files from their local machine into the browser-based RDP session.
  • Remote RDP session to client allowed — Users can download files from the browser-based RDP session to their local machine.
  • Both directions allowed — Users can upload and download files between their local machine and the browser-based RDP session. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Browser Isolation unterstützt Authorization Proxy Endpoints

Browser Isolation unterstützt nun Gateway Authorization Proxy Endpoints, sodass identitätsbasierte HTTP-Isolate-Richtlinien auch für über PAC-Dateien geleiteten Datenverkehr ohne Cloudflare One Client greifen.

Browser Isolation now supports Gateway authorization proxy endpoints. You can apply HTTP Isolate policies to traffic routed through authorization proxy endpoints, the same way you can for traffic from the Cloudflare One Client.

Previously, only source IP proxy endpoints supported Browser Isolation, and only with non-identity policies. Because authorization proxy endpoints authenticate users through an identity provider, you can now apply identity-based Isolate policies to PAC file-proxied traffic without requiring the Cloudflare One Client.

To get started, create an authorization proxy endpoint and build an Isolate policy.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Virtual Appliance selbst im Dashboard registrieren

Eine Cloudflare One Virtual Appliance lässt sich nun selbst im Dashboard registrieren und der Lizenzschlüssel generieren oder neu erzeugen, ohne das Account-Team zu kontaktieren.

You can now register a Cloudflare One Virtual Appliance and generate its license key directly from the dashboard, without contacting your account team.

Registering a Cloudflare One Virtual Appliance and generating its authentication key from the Connectors page

  • On the Connectors page, select Add an appliance and choose Virtual appliance to register a virtual appliance and generate its authentication key.
  • Use Regenerate authentication key from a virtual appliance connector's menu to rotate its key. The previous key is immediately and irrevocably revoked.
  • The authentication key is shown only once — copy and store it securely.

This complements the existing API and Terraform self-serve workflow for provisioning virtual appliances. Hardware appliances continue to use the existing account-team fulfillment workflow.

For details, refer to Configure a Cloudflare One Virtual Appliance.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Hostname-Routing für Cloudflare Mesh

Zu einem Cloudflare Mesh Node lassen sich jetzt zusätzlich zu CIDR-Routen auch Hostname-Routen für private oder öffentliche Hostnamen hinzufügen.

You can now add hostname routes to a Cloudflare Mesh node, in addition to CIDR routes.

  1. Client device

    Requests wiki.internal.local

  2. DNS query↓

  3. Cloudflare Gateway

    Returns a token IP, then rewrites the destination to the real private IP.

    172.64.128.0/20

  4. Hostname route↓

  5. Mesh node

    Forwards traffic to the host on the local network

  6. ↓

  7. Private host

    wiki.internal.local · 10.0.0.50

Instead of managing IP ranges, you can attract traffic for a hostname to a Mesh node:

  • Private hostname (for example, wiki.internal.local) — reach an internal application by name, which is useful when it has an unknown or ephemeral IP. On Mesh you do not need to run a DNS server; a local hosts-file entry on the node is enough, or you can use a Gateway resolver policy for split DNS.
  • Public hostname (for example, www.example.com) — route that hostname's traffic through the node and egress via the node's public IP.

Go to Mesh ↗ …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.6.836.0

Die Version entspricht 2026.6.822.0, behebt aber ein Problem im RPM-Paket, sodass das Repository nun für jede Betriebssystemversion den passenden Build mit den richtigen Abhängigkeiten liefert; Debian und Ubuntu waren nicht betroffen.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This package is the same release as 2026.6.822.0, with a fix for our RPM package. Previously the repository served a single build to every OS version, so an install could pull a dependency that isn't available on that release. The repository now serves the correct build for each operating system version, so installs automatically pull the dependencies that version requires. Debian and Ubuntu were not affected.

If you installed version 2026.6.822.0 on an RPM-based distribution, we recommend refreshing your repository configuration:

sudo curl -fsSL https://pkg.cloudflareclient.com/cloudflare-warp-ascii.repo | sudo tee /etc/yum.repos.d/cloudflare-warp.repo
sudo dnf clean all
sudo dnf install cloudflare-warp

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Korrekte URL-Fragmente bei Redirects für SPAs

Access erhält beim Redirect nach dem Login nun die Zeichen in URL-Fragmenten (/, ?, =, &, ;) und behebt damit fehlerhafte Navigation bei Single-Page-Applications ohne Konfigurationsänderung.

Access now correctly preserves URL fragment characters (/, ?, =, &, ;) when redirecting users back to an application after login. Previously, these characters were encoded with encodeURIComponent, which mangled fragment-based routes used by single-page applications (SPAs).

For example, an SPA URL like https://app.example.com/#/dashboard?tab=settings&view=advanced would previously redirect to a broken URL after login. This is now handled correctly.

If your SPA users were experiencing broken navigation after authenticating through Access, this fix resolves the issue without any configuration changes.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Unabhängige MFA für Infrastruktur-Anwendungen

Access for Infrastructure unterstützt nun unabhängige Multi-Faktor-Authentifizierung für SSH-Verbindungen mit YubiKey PIV-Schlüsseln, konfigurierbar pro Anwendung und Policy samt MFA-Sitzungsdauer.

Access for Infrastructure now supports independent multi-factor authentication (MFA) for SSH connections using YubiKey PIV keys. This adds a hardware-backed second factor to SSH access, ensuring that a compromised device session alone is not sufficient to reach your servers.

With per-application and per-policy configuration, you can enforce PIV key authentication for sensitive usernames (for example, root) while applying different requirements for other usernames. You can also set an MFA session duration to control how often users must re-authenticate.

Enrollment

Users enroll their YubiKey PIV key through the App Launcher. For enrollment instructions and SSH client setup, refer to Enroll a PIV key for infrastructure apps.

Configuration

For setup instructions, refer to Enforce MFA for infrastructure applications.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Rollen für Gateway-Policies und Zero-Trust-Listen

Für Gateway-Firewall-Policies und Zero-Trust-Listen gibt es neue ressourcenbezogene Rollen, mit denen Administratoren gezielt Zugriff auf bestimmte Policy-Typen oder Listenverwaltung delegieren können, ohne kontoweite Rechte zu vergeben.

You can now assign granular, resource-scoped roles for Cloudflare Gateway firewall policies and Zero Trust lists. Administrators can delegate access to specific policy types or list management without granting account-wide or product-wide control.

What is new

When you add a member or create a permission policy, the following resource-scoped roles are now available:

Role

Description

Zero Trust Gateway Firewall Policies Admin

Can view and edit all Gateway firewall policies, including DNS, HTTP, and Network policies.

Zero Trust Gateway DNS Policies Admin

Can view and edit Gateway DNS policies.

Zero Trust Gateway HTTP Policies Admin

Can view and edit Gateway HTTP policies.

Zero Trust Gateway Network Policies Admin

Can view and edit Gateway Network policies.

Zero Trust Gateway Egress Policies Admin

Can view and edit Gateway Egress policies.

Zero Trust Gateway Resolver Policies Admin

Can view and edit Gateway Resolver policies.

Zero Trust Gateway Policies Admin

Can view and edit all Gateway policies.

Zero Trust Gateway Policies Read

Can view all Gateway policies.

Zero Trust Gateway Read Only

Can view all Gateway resources. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.6.822.0 (GA)

Das GA-Release des Cloudflare One Client für Windows übernimmt Funktionen aus der Beta, darunter per Device Profile bzw. Network Policy verteilte DNS-Suchsuffixe und eine per MDM aktivierbare Pflichtauthentifizierung, die bis zur Anmeldung des Nutzers den gesamten Internetverkehr blockiert.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This release introduces multiple features from our previous beta release into stable release, including:

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details.
  • Added mandatory authentication. When enabled via MDM, the Cloudflare One Client blocks all Internet traffic from the moment the machine boots until the user authenticates, closing the visibility gap on newly deployed devices. See the announcement blog and documentation for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.6.822.0

Das GA-Release bringt Beta-Funktionen in die stabile Version, darunter DNS-Suchsuffixe aus Device Profile bzw. Network Policy und hardwaregestützte Geräteregistrierung über die Secure Enclave.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This release introduces multiple features from our previous beta release into stable release, including:

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details.
  • Upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the Secure Enclave whenever available to provide stronger protection against device impersonation. See Hardware-backed registration for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.6.822.0

Das GA-Release bringt Beta-Funktionen in die stabile Version, darunter DNS-Suchsuffixe aus Device Profile bzw. Network Policy und hardwaregestützte Geräteregistrierung über das TPM (ab TPM 2.0).

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This release introduces multiple features from our previous beta release into stable release, including:

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details.
  • Upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the TPM (with TPM 2.0+) whenever it is available to provide stronger protection against device impersonation. See Hardware-backed registration for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Service-Token-Unterstützung für MCP-Server-Portale

Autonome Agenten und Bots können sich nun mit einem Access Service Token ohne browserbasierten OAuth-Ablauf mit einem MCP-Server-Portal verbinden, sofern Service-Auth-Policies eingerichtet und „Require user auth“ für die verknüpften Server deaktiviert ist.

You can now connect autonomous agents and bots to an MCP server portal using an Access service token. Service token sessions can reach upstream MCP servers through the portal without a browser-based OAuth flow.

To set this up:

  • Add a Service Auth policy that matches your service token to the portal's Access application.
  • Add a Service Auth policy that matches the same token to each linked MCP server's Access application.
  • Turn Require user auth off (on_behalf: false) for each linked server so the portal uses the admin credential instead of a per-user OAuth grant.

The bot connects with CF-Access-Client-Id and CF-Access-Client-Secret headers and sees the tools from every linked server it is authorized for. Servers that still require per-user OAuth are excluded from service token sessions because a service token cannot complete a per-user OAuth grant.

For step-by-step setup, refer to Connect with a service token.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS Beta 2026.6.782.1

Das Beta-Release führt hardwaregestützte Geräteregistrierung über die Secure Enclave ein und bringt Verbesserungen wie besseren Hochkontrast-Support, standardmäßig aktiviertes PMTUD sowie Fixes bei DNS-Abfragen nach Leerlauf und mehrere UI-Korrekturen.

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.

This beta release introduces upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the Secure Enclave whenever available to provide stronger protection against device impersonation.

Additional changes and improvements

This release also introduces multiple fixes and improvements including:

  • Improved accessibility by using high contrast colors and more defined color boundaries when high contrast is enabled in the macOS Display settings.
  • Path MTU Discovery (PMTUD) is now enabled by default.
  • Fixed an issue where DNS queries would fail after the connection was idle, requiring users to retry.
  • Users can now register with team names in any case format without errors.
  • New UI fixes
    • Fixed an issue where users with invalid MDM configurations were returned to the onboarding screen after successful authentication.
    • Added a re-auth button and banner to the home screen so users don't miss it when their session expires.
    • Added clear error messaging when the Cloudflare certificate needs to be installed.
    • Brought back support for pausing the tunnel when connected to user-specified Wi-Fi networks for consumer users. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Regionalized IP Bindings für Regional Services

Regional Services unterstützt nun Regionalized IP Bindings, mit denen sich CIDRs aus eigenen BYOIP-Präfixen an eine Region binden lassen, sodass TLS-Terminierung und Verarbeitung nur in Rechenzentren dieser Region erfolgen.

Regional Services now supports Regionalized IP Bindings, letting you regionalize traffic at the IP layer for prefixes you bring to Cloudflare through Bring Your Own IP (BYOIP).

Where Regional Hostnames regionalize traffic by hostname, Regionalized IP Bindings let you bind a CIDR from one of your prefixes to a region — ideal for address-map deployments and any service you address by IP rather than hostname. Cloudflare then terminates TLS and processes traffic to those addresses only within the data centers in that region.

Regionalized IP Bindings requires the Regional Services and Regional Services for BYOIP entitlements. Contact your account team to enable them.

To get started, refer to Regionalized IP Bindings.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Alle Routen auf einer Seite im Dashboard verwalten

Die Routes-Seite im Cloudflare-Dashboard zeigt jetzt Routen von Mesh, Tunnel, Cloudflare WAN und Magic Transit in einer Tabelle samt interaktiver Karte und erlaubt das Erstellen, Bearbeiten und Löschen, wobei der Next Hop bei WAN- und Magic-Transit-Routen per Connector-Name gewählt wird.

The Routes page in the Cloudflare dashboard now shows the routes across all of your connectors — Cloudflare Mesh and Cloudflare Tunnel routes alongside Cloudflare WAN and Magic Transit static routes — in a single table, instead of a separate routes view per product.

The unified Routes page in the Cloudflare dashboard, showing routes across connectors in a single table

From the unified Routes page you can:

  • Visualize your network with an interactive map that shows how your destinations flow through to your connectors — including equal-cost multi-path (ECMP) routes where the same prefix is served by several connectors. Select a node to filter the table down to the routes behind it.
  • See every route in one table, with its destination, type, connector, priority, and source, and filter or sort to find what you need.
  • Create, edit, and delete routes of any supported type without leaving the page. When adding a Cloudflare WAN or Magic Transit static route, you now pick the next hop by connector name instead of typing its IP. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Identity Provider ist Standard für neue Konten

Neue Zero-Trust-Organisationen erhalten nun den Cloudflare Identity Provider statt One-time PIN als Standard-Anmeldemethode, während bestehende Organisationen unverändert bleiben.

When you create a new Zero Trust organization, Cloudflare now adds the Cloudflare identity provider as your default login method. Previously, new organizations started with one-time PIN (OTP).

With the Cloudflare identity provider, your users authenticate using their existing Cloudflare account credentials, and authentication is restricted to members of your account. You can still add OTP or connect any third-party identity provider whenever you need to.

This change only applies to newly created accounts. Existing organizations keep the login methods they already have configured. If you would like to use the Cloudflare Identity Provider in an existing account, you must enable it.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Eigene Themen für den Schutz von KI-Prompts

Cloudflare DLP erlaubt nun benutzerdefinierte Themen für den KI-Prompt-Schutz, die in natürlicher Sprache beschrieben werden und kontextbasiert statt per Schlüsselwort erkannt werden, verfügbar für ChatGPT, Google Gemini, Perplexity und Claude.

You can now define custom topics for AI prompt protection. Predefined AI prompt topics cover common content and intent categories such as PII, source code, and jailbreak attempts. Custom topics let you detect unique or proprietary concepts that are not included in predefined categories.

You describe a custom topic in natural language, and Cloudflare DLP detects whether a prompt matches that topic based on context rather than specific keywords. For example, a topic that describes confidential merger discussions matches a prompt that paraphrases the deal, even when the prompt never uses the word merger or names the companies involved. To detect literal values such as internal codenames or product identifiers, use a custom wordlist or pattern entry instead.

Custom topics run through the same application granular controls path as predefined AI prompt topics. Custom topics are available for ChatGPT, Google Gemini, Perplexity, and Claude.

Create a custom AI prompt topic

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway-Policies für öffentlichen Internetverkehr von Workers

Workers mit VPC-Network-Binding network_id "cf1:network" leiten Verkehr zu öffentlichen Zielen nun über Cloudflare Gateway, sodass bestehende DNS-, HTTP-, Network- und Egress-Policies auch für ihren Datenverkehr gelten.

Workers using a VPC Network binding with network_id: "cf1:network" now egress to public Internet destinations through Cloudflare Gateway. This means your existing Zero Trust traffic policies — DNS, HTTP, Network, and egress — extend to traffic that originates from your Workers, the same way they do for WARP users today.

  1. Worker

    Calls env.EGRESS.fetch()

  2. VPC binding↓

  3. Cloudflare Mesh

    Bind via cf1:network

  4. ↓

  5. Cloudflare Gateway

    Policies applied:

    DNSHTTPNetwork

  6. ↓

  7. ↗Public Internet

    Any public hostname or IP

Gateway logsDNSHTTPNetwork

What you get by default: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Identity Provider per IdP-Federation kontenübergreifend teilen

Cloudflare Access unterstützt IdP-Federation, sodass ein einmal in einem Quellkonto konfigurierter Identity Provider mit anderen Konten der Organisation geteilt werden kann, mit automatischer Bereitstellung und unveränderlichen Verbindungen in den Empfängerkonten.

Cloudflare Access now supports IdP federation, which allows organizations to share a single identity provider across multiple Cloudflare accounts.

Instead of configuring the same IdP (for example, Okta or Entra ID) separately in every account, you configure it once in a source account and share it with the other accounts in your organization. Each recipient account gets a read-only IdP connection that routes authentication back to the source account through a bridge — a hidden application in the source account that brokers the cross-account login. End users sign in with their existing IdP credentials, and each account's Access policies evaluate the resulting identity just like any other IdP login.

Key capabilities:

  • One IdP, many accounts — Configure your IdP once and share it with all accounts in your organization.
  • Lifecycle management — As accounts join or leave your Cloudflare organization, their IdP connections are provisioned and removed automatically — no manual cleanup required.
  • Immutable recipient connections — IdP connections in recipient accounts cannot be accidentally modified or deleted.

To get started, refer to IdP federation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: SAML-Assertion-Verschlüsselung für Identitätsanbieter

Cloudflare Access unterstützt jetzt die Verschlüsselung von SAML-Assertions mit einem von Cloudflare verwalteten Zertifikat, inklusive automatischer Zertifikatserzeugung, Rotation ohne Ausfallzeit und PEM-Export.

Cloudflare Access now supports SAML assertion encryption for identity provider integrations. When turned on, your identity provider encrypts SAML assertions using a Cloudflare-managed certificate before sending them through the user's browser. Only Access can decrypt these assertions, protecting sensitive identity data even after TLS termination.

Without encryption, SAML assertions are transmitted in plaintext and could be visible to browser extensions or client-side malware.

SAML encryption toggle in the identity provider configuration

SAML encryption includes built-in certificate lifecycle management:

  • Automatic certificate generation: Access generates an encryption certificate when you turn on SAML encryption for an identity provider.
  • Certificate rotation: Rotate certificates without downtime. The previous certificate remains valid until expiration, giving you time to update your IdP.
  • PEM export: Copy the certificate in PEM format for manual upload to your IdP, or point your IdP to the SAML metadata endpoint for automatic retrieval.

To get started, refer to Encrypt SAML assertions.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One Updates & Release Notes (Cloudflare) – Oktober 2026 (Seite 5) | updatefeed