Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Streaming-Scan von ZIP-Dateien ohne Größenlimit pro Datei

DLP scannt ZIP-Dateien nun per Streaming Element für Element, wodurch frühere Dateigrößenbeschränkungen entfallen, der Speicherverbrauch sinkt und auch Office-Dokumente (DOCX, XLSX, PPTX) profitieren, ganz ohne Konfigurationsänderung.

DLP now processes ZIP files using a streaming handler that scans archive contents element-by-element as data arrives. This removes previous file size limitations and improves memory efficiency when scanning large archives.

Microsoft Office documents (DOCX, XLSX, PPTX) also benefit from this improvement, as they use ZIP as a container format.

This improvement is automatic — no configuration changes are required.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: HAR-Dateien erkennen und bereinigen

Gateway enthält ein vordefiniertes DLP-Profil namens Unsanitized HAR, mit dem sich HAR-Datei-Uploads in HTTP-Richtlinien blockieren oder auf ein Bereinigungstool umleiten lassen.

HTTP Archive (HAR) files are used by engineering and support teams to capture and share web traffic logs for troubleshooting. However, these files routinely contain highly sensitive data — including session cookies, authorization headers, and other credentials — that can pose a significant risk if uploaded to third-party services without being reviewed or cleaned first.

Gateway now includes a predefined DLP profile called Unsanitized HAR that detects HAR files in HTTP traffic. You can use this profile in a Gateway HTTP policy to either block HAR file uploads entirely or redirect users to a sanitization tool before allowing the upload to proceed.

How to configure a HAR file policy

In the Cloudflare dashboard ↗︎, go to Zero Trust > Traffic policies > Firewall Policies > HTTP and create a new HTTP policy using the DLP Profile selector:

Selector

Operator

Value

Action

DLP Profile

in

Unsanitized HAR

Then choose one of the following actions:

  • Block: Prevents the upload of any HAR file that has not been sanitized by Cloudflare's sanitizer. Use this for strict environments where HAR file sharing must be disallowed entirely. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway: OIDC-Claims-Filter in Firewall-, Resolver- und Egress-Richtlinien

Cloudflare Gateway unterstützt OIDC Claims jetzt als Selektor in Firewall-, Resolver- und Egress-Richtlinien, sodass Administratoren identitätsbasierte Richtlinien anhand benutzerdefinierter Claims des Identity Providers erstellen können.

Cloudflare Gateway now supports OIDC Claims as a selector in Firewall, Resolver, and Egress policies. Administrators can use custom OIDC claims from their identity provider to build fine-grained, identity-based traffic policies across all Gateway policy types.

With this update, you can:

  • Filter traffic in DNS, HTTP, and Network firewall policies based on OIDC claim values.
  • Apply custom resolver policies to route DNS queries to specific resolvers depending on a user's OIDC claims.
  • Control egress policies to assign dedicated egress IPs based on OIDC claim attributes.

For example, you can create a policy that routes traffic differently for users with department=engineering in their OIDC claims, or restrict access to certain destinations based on a user's role claim. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Managed OAuth für Cloudflare Access

Cloudflare Access unterstützt Managed OAuth, womit sich Nicht-Browser-Clients wie CLIs, KI-Agenten, SDKs und Skripte per OAuth-2.0-Authorization-Code-Flow an geschützten Anwendungen anmelden können; die Funktion ist für bestehende Anwendungen optional.

Cloudflare Access supports managed OAuth, which allows non-browser clients — such as CLIs, AI agents, SDKs, and scripts — to authenticate with Access-protected applications using a standard OAuth 2.0 authorization code flow.

Previously, non-browser clients that attempted to access a protected application received a 302 redirect to a login page they could not complete. The established workaround was cloudflared access curl, which required installing additional tooling.

With managed OAuth, clients instead receive a 401 response with a WWW-Authenticate header that points to Access's OAuth discovery endpoints (RFC 8414 ↗︎ and RFC 9728 ↗︎). The client opens the end user's browser to the Access login page. The end user authenticates with their identity provider, and the client receives an OAuth access token for subsequent requests.

Access enforces the same policies as a browser login; the OAuth layer is a new transport mechanism, not a separate authentication path.

Managed OAuth can be enabled on any self-hosted Access application or MCP server portal. It is opt-in for existing applications to avoid interfering with those that run their own OAuth servers and rely on their own WWW-Authenticate headers.

Note …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

MCP-Portal-Traffic über Cloudflare Gateway leiten

MCP server portals können Traffic jetzt über Cloudflare Gateway routen, was detailliertere HTTP-Logs und DLP-Scans für Daten an Upstream-MCP-Server ermöglicht; die Option wird in den AI controls des Portals aktiviert.

MCP server portals can now route traffic through Cloudflare Gateway for richer HTTP request logging and data loss prevention (DLP) scanning.

When Gateway routing is turned on, portal traffic appears in your Gateway HTTP logs. You can create Gateway HTTP policies with DLP profiles to detect and block sensitive data sent to upstream MCP servers.

Note

DLP AI prompt profiles do not apply to MCP server portal traffic.

To enable Gateway routing, go to Access controls > AI controls, edit the portal, and turn on Route traffic through Cloudflare Gateway under Basic information.

Route MCP server portal traffic through Cloudflare Gateway …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Tunnel: Logs mehrerer Replicas gleichzeitig streamen

Die Übersichtsseite eines Cloudflare Tunnel zeigt im Dashboard nun alle Replicas an und erlaubt es, die Logs mehrerer Replicas gleichzeitig zu streamen, statt wie zuvor nur eines.

In the Cloudflare One dashboard, the overview page for a specific Cloudflare Tunnel now shows all replicas of that tunnel and supports streaming logs from multiple replicas at once.

View replicas and stream logs from multiple connectors

Previously, you could only stream logs from one replica at a time. With this update:

  • Replicas on the tunnel overview — All active replicas for the selected tunnel now appear on that tunnel's overview page under Connectors. Select any replica to stream its logs.
  • Multi-connector log streaming — Stream logs from multiple replicas simultaneously, making it easier to correlate events across your infrastructure during debugging or incident response. To try it out, log in to Cloudflare One ↗︎ and go to Networks > Connectors > Cloudflare Tunnels. Select View logs next to the tunnel you want to monitor. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Unbegrenztes Paging in Investigations

Investigations unterstützen in Dashboard und API unbegrenztes Result-Paging ohne die frühere Grenze von 1.000 Datensätzen, und die API liefert nun bis zu 10.000 Datensätze pro Seite.

Investigations now support unlimited result paging in both the dashboard and the API, removing the previous 1,000-record cap. Security teams can page through complete result sets when searching across large mail volumes, giving SOC analysts and automated workflows deeper visibility for forensics and threat hunting.

In the dashboard, infinite paging is now supported in the Investigations view. The 1,000-record ceiling has been removed, so you can navigate through the full result set directly in the UI. The Investigations API now returns up to 10,000 records per page (up from 1,000), with no cap on total result volume across pages.

For high-volume use cases, we recommend:

  • Logpush to a SIEM for full-fidelity datasets and long-term retention.
  • SOAR playbooks against the async bulk action API for large-scale remediation. Bulk actions initiated from the dashboard remain capped at 1,000 messages per action.
  • The Investigations API for report exports larger than 1,000 results, which is the dashboard download cap.

This applies to all Email Security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP client für macOS 2026.3.566.1 (Beta)

Das Beta-Release des WARP client für macOS bringt eine neue Oberfläche mit Button statt Schalter und einklappbarer Navigationsleiste sowie mehrere Fehlerbehebungen, etwa bei leeren MDM-Dateien, Proxy-Mode-Hängern und dem Wechsel zwischen Organisationen.

A new Beta release for the macOS WARP client is now available on the beta releases downloads page.

This release contains minor fixes and introduces a brand new visual style for the client interface. The new Cloudflare One Client interface changes connectivity management from a toggle to a button and brings useful connectivity settings to the home screen. The redesign also introduces a collapsible navigation bar. When expanded, more client information can be accessed including connectivity, settings, and device profile information. If you have any feedback or questions, visit the Cloudflare Community forum and let us know.

Changes and improvements

  • Empty MDM files are now rejected instead of being incorrectly accepted as a single MDM config.
  • Fixed an issue in proxy mode where the client could become unresponsive due to upstream connection timeouts.
  • Fixed emergency disconnect state from a previous organization incorrectly persisting after switching organizations.
  • Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  • Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  • Added monitoring for tunnel statistics collection timeouts. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP client für Windows 2026.3.566.1 (Beta)

Das Beta-Release des WARP client für Windows bringt eine neue Oberfläche, Cubic als Congestion-Control-Algorithmus für den Tunnel, zusätzliche QUIC-Metriken in Diagnoseprotokollen sowie Fehlerbehebungen bei Paketmitschnitt und RDP-Registrierungen im Multi-User-Modus.

A new Beta release for the Windows WARP client is now available on the beta releases downloads page.

This release contains minor fixes and introduces a brand new visual style for the client interface. The new Cloudflare One Client interface changes connectivity management from a toggle to a button and brings useful connectivity settings to the home screen. The redesign also introduces a collapsible navigation bar. When expanded, more client information can be accessed including connectivity, settings, and device profile information. If you have any feedback or questions, visit the Cloudflare Community forum and let us know.

Changes and improvements

  • Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  • Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  • Added monitoring for tunnel statistics collection timeouts.
  • Switched tunnel congestion control algorithm to Cubic for improved reliability across platforms.
  • Fixed packet capture failing on tunnel interface when the tunnel interface is renamed by SCCM VPN boundary support.
  • Fixed unnecessary registration deletion caused by RDP connections in multi-user mode. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

User Risk Score als Selektor in Access-Richtlinien

In Access-Richtlinien lässt sich jetzt der Selektor User Risk Score verwenden, um auf erkannte Verhaltensmuster wie Impossible Travel oder viele DLP-Treffer zu reagieren.

You can now use user risk scores in your Access policies. The new User Risk Score selector allows you to create Access policies that respond to user behavior patterns detected by Cloudflare's risk scoring system, including impossible travel, high DLP policy matches, and more.

For more information, refer to Use risk scores in Access policies.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway Authorization Proxy und gehostete PAC-Dateien (Open Beta)

Der Gateway Authorization Proxy und das Hosting von PAC-Dateien sind für alle Tarife in der Open Beta und ersetzen die IP-basierte Autorisierung durch Cloudflare-Access-Authentifizierung, ohne dass der WARP client nötig ist.

The Gateway Authorization Proxy and PAC file hosting are now in open beta for all plan types.

Previously, proxy endpoints relied on static source IP addresses to authorize traffic, providing no user-level identity in logs or policies. The new authorization proxy replaces IP-based authorization with Cloudflare Access authentication, verifying who a user is before applying Gateway filtering without installing the WARP client.

This is ideal for environments where you cannot deploy a device client, such as virtual desktops (VDI), mergers and acquisitions, or compliance-restricted endpoints.

Key capabilities

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare-One-Ressourcen als JSON oder POST-Request kopieren

Im Dashboard lassen sich unterstützte Cloudflare-One-Ressourcen wie Access-Anwendungen und Gateway-Richtlinien über das Überlaufmenü als JSON oder als fertiger API-POST-Request kopieren.

You can now copy Cloudflare One resources as JSON or as a ready-to-use API POST request directly from the dashboard. This makes it simple to transition workflows into API calls, automation scripts, or infrastructure-as-code pipelines.

To use this feature, click the overflow menu (⋮) on any supported resource and select Copy as JSON or Copy as POST request. The copied output includes only the fields present on your resource, giving you a clean and minimal starting point for your own API calls.

Initially supported resources:

  • Access applications
  • Access policies
  • Gateway policies
  • Resolver policies
  • Service tokens
  • Identity providers

We will continue to add support for more resources throughout 2026.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Zwischenablage-Steuerung für browserbasiertes RDP

Für browserbasiertes RDP mit Cloudflare Access lässt sich pro Richtlinie festlegen, ob Kopieren und Einfügen zwischen lokalem Rechner und Remote-Sitzung in jede Richtung erlaubt ist, wobei neue Richtlinien beides standardmäßig verbieten.

You can now configure clipboard controls for browser-based RDP with Cloudflare Access. Clipboard controls allow administrators to restrict whether users can copy or paste text between their local machine and the remote Windows server.

Enable users to copy and paste content from their local machine to remote RDP sessions in the Cloudflare One dashboard

This feature is useful for organizations that support bring-your-own-device (BYOD) policies or third-party contractors using unmanaged devices. By restricting clipboard access, you can prevent sensitive data from being transferred out of the remote session to a user's personal device.

Configuration options

Clipboard controls are configured per policy within your Access application. For each policy, you can independently allow or deny:

  • Copy from local client to remote RDP session — Users can copy/paste text from their local machine into the browser-based RDP session.
  • Copy from remote RDP session to local client — Users can copy/paste text from the browser-based RDP session to their local machine.

By default, both directions are denied for new policies. For existing Access applications created before this feature was available, clipboard access remains enabled to preserve backwards compatibility. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

MCP-Portal-Logs per Logpush exportieren

MCP server portals unterstützen Logpush, sodass Aktivitätsprotokolle automatisch an Speicherziele oder SIEM-Tools exportiert werden können; die Funktion ist nur in Enterprise-Tarifen verfügbar.

Availability

Only available on Enterprise plans.

MCP server portals now supports Logpush integration. You can automatically export MCP server portal activity logs to third-party storage destinations or security information and event management (SIEM) tools for analysis and auditing.

Available log fields

The MCP server portal logs dataset includes fields such as:

  • Datetime — Timestamp of the request
  • PortalID / PortalAUD — Portal identifiers
  • ServerID / ServerURL — Upstream MCP server details
  • Method — JSON-RPC method (for example, tools/call, prompts/get, resources/read)
  • ToolCallName / PromptGetName / ResourceReadURI — Method-specific identifiers
  • UserID / UserEmail — Authenticated user information
  • Success / Error — Request outcome
  • ServerResponseDurationMs — Response time from upstream server

For the complete field reference, refer to MCP portal logs.

Set up Logpush

To configure Logpush for MCP server portal logs, refer to Logpush integration.

Note

MCP server portals is currently in beta.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Protokolle für Gateway Protocol Detection (Beta)

Die Gateway Protocol Detection erkennt in der Beta zusätzlich IMAP, POP3, SMTP, MYSQL, RSYNC-DAEMON, LDAP und NTP, die im Selektor Detected Protocol von Network policies nutzbar sind.

Gateway Protocol Detection now supports seven additional protocols in beta:

Protocol

Notes

IMAP

Internet Message Access Protocol — email retrieval

POP3

Post Office Protocol v3 — email retrieval

SMTP

Simple Mail Transfer Protocol — email sending

MYSQL

MySQL database wire protocol

RSYNC-DAEMON

rsync daemon protocol

LDAP

Lightweight Directory Access Protocol

NTP

Network Time Protocol

These protocols join the existing set of detected protocols (HTTP, HTTP2, SSH, TLS, DCERPC, MQTT, and TPKT) and can be used with the Detected Protocol selector in Network policies to identify and filter traffic based on the application-layer protocol, without relying on port-based identification.

If protocol detection is enabled on your account, these protocols will automatically be logged when detected in your Gateway network traffic.

For more information on using Protocol Detection, refer to the Protocol detection documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP client für Windows 2026.1.150.0

Das GA-Release des WARP client für Windows verbessert den Multi-User-Modus, deaktiviert NetBIOS over TCP/IP standardmäßig (in Geräteprofilen aktivierbar) und behebt einen Fehler bei der Local-Network-Exclusion mit Timeout 0.

A new GA release for the Windows WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features.

Changes and improvements

  • Improvements to multi-user mode. Fixed an issue where when switching from a pre-login registration to a user registration, Mobile Device Management (MDM) configuration association could be lost.
  • Added a new feature to manage NetBIOS over TCP/IP functionality on the Windows client. NetBIOS over TCP/IP on the Windows client is now disabled by default and can be enabled in device profile settings.
  • Fixed an issue causing failure of the local network exclusion feature when configured with a timeout of 0. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP client für macOS 2026.1.150.0

Das GA-Release des WARP client für macOS behebt Fehler bei der Local-Network-Exclusion mit Timeout 0, bei DNS-Konfiguration, bei DEX-HTTP-Tests und bei DNS-Anfragen im Modus Traffic and DNS und meldet Colocation-Daten genauer.

A new GA release for the macOS WARP client is now available on the stable releases downloads page.

This release contains minor fixes and improvements.

Changes and improvements

  • Fixed an issue causing failure of the local network exclusion feature when configured with a timeout of 0.
  • Improvement for more accurate reporting of device colocation information in the Cloudflare One dashboard.
  • Fixed an issue with DNS server configuration failures that caused tunnel connection delays.
  • Fixed an issue where misconfigured DEX HTTP tests prevented new registrations.
  • Fixed an issue causing DNS requests to fail with clients in Traffic and DNS mode.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP client für Linux 2026.1.150.0

Das GA-Release des WARP client für Linux behebt Fehler bei der Local-Network-Exclusion mit Timeout 0, bei DEX-HTTP-Tests und bei DNS-Anfragen in den Modi Traffic and DNS sowie DNS only und verbessert die Colocation-Meldung.

A new GA release for the Linux WARP client is now available on the stable releases downloads page.

This release contains minor fixes and improvements.

WARP client version 2025.8.779.0 introduced an updated public key for Linux packages. The public key must be updated if it was installed before September 12, 2025 to ensure the repository remains functional after December 4, 2025. Instructions to make this update are available at pkg.cloudflareclient.com.

Changes and improvements

  • Fixed an issue causing failure of the local network exclusion feature when configured with a timeout of 0.
  • Improvement for more accurate reporting of device colocation information in the Cloudflare One dashboard.
  • Fixed an issue where misconfigured DEX HTTP tests prevented new registrations.
  • Fixed issues causing DNS requests to fail with clients in Traffic and DNS mode or DNS only mode.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Cloudy Summaries erklären Posture Findings

Cloudy Summaries in CASB erzeugen mit Cloudflares Cloudy AI automatisch verständliche Zusammenfassungen zu Posture Findings, die in den Finding-Details unter „Cloud and SaaS findings“ angezeigt werden und für alle unterstützten Integrationen wie Microsoft 365, Google Workspace oder Salesforce verfügbar sind.

You can now easily understand your SaaS security posture findings and why they were detected with Cloudy Summaries in CASB. This feature integrates Cloudflare's Cloudy AI directly into your CASB Posture Findings to automatically generate clear, plain-language summaries of complex security misconfigurations, third-party app risks, and data exposures.

This allows security teams and IT administrators to drastically reduce triage time by immediately understanding the context, potential impact, and necessary remediation steps for any given finding—without needing to be an expert in every connected SaaS application.

To view a summary, simply navigate to your Posture Findings in the Cloudflare One dashboard (under Cloud and SaaS findings) and open the finding details of a specific instance of a Finding.

Cloudy Summaries are supported on all available integrations, including Microsoft 365, Google Workspace, Salesforce, GitHub, AWS, Slack, and Dropbox. See the full list of supported integrations here.

Key capabilities

  • Contextual explanations — Quickly understand the specifics of a finding with plain-language summaries detailing exactly what was detected, from publicly shared sensitive files to risky third-party app scopes. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Tunnel jetzt im Haupt-Dashboard verwaltbar

Cloudflare Tunnel lässt sich nun im Haupt-Cloudflare-Dashboard unter Networking > Tunnels erstellen, konfigurieren, löschen und überwachen, inklusive Auswahl nach Namen bei DNS-Einträgen und Workers VPC sowie Echtzeit-Einblick in Replicas und Health-Status.

Cloudflare Tunnel is now available in the main Cloudflare Dashboard at Networking > Tunnels ↗︎, bringing first-class Tunnel management to developers using Tunnel for securing origin servers.

Manage Tunnels in the Core Dashboard

This new experience provides everything you need to manage Tunnels for public applications, including:

  • Full Tunnel lifecycle management: Create, configure, delete, and monitor all your Tunnels in one place.
  • Native integrations: View Tunnels by name when configuring DNS records and Workers VPC — no more copy-pasting UUIDs.
  • Real-time visibility: Monitor replicas and Tunnel health status directly in the dashboard. …

Originalquelle(öffnet in neuem Tab)Problem melden