Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Application Security von Cloudflare

WAF-Erkennung für Oracle Identity Manager

Eine neue WAF-Regel erkennt Angriffe auf die kritische Schwachstelle CVE-2025-61757 im Oracle Identity Manager und blockiert diese.

This week’s release introduces a critical detection for CVE-2025-61757, a vulnerability in the Oracle Identity Manager REST WebServices component.

Key Findings

This flaw allows unauthenticated attackers with network access over HTTP to fully compromise the Identity Manager, potentially leading to a complete takeover.

Impact

Oracle Identity Manager (CVE-2025-61757): Exploitation could allow an unauthenticated remote attacker to bypass security checks by sending specially crafted requests to the application's message processor. This enables the creation of arbitrary employee accounts, which can be leveraged to modify system configurations and achieve full system compromise.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...39fdbe7e

N/A

Oracle Identity Manager - Pre-Auth RCE - CVE:CVE-2025-61757

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Terraform v5.13.0 verfügbar

Der Terraform-Provider für Cloudflare wurde in Version 5.13.0 veröffentlicht, mit neuen Funktionen, Ressourcen und einer Breaking Change für cloudflare_api_token und cloudflare_account_token.

Earlier this year, we announced the launch of the new Terraform v5 Provider. We are aware of the high number of issues reported by the Cloudflare community related to the v5 release. We have committed to releasing improvements on a 2-3 week cadence ↗︎ to ensure its stability and reliability, including the v5.13 release. We have also pivoted from an issue-to-issue approach to a resource-per-resource approach ↗︎ - we will be focusing on specific resources to not only stabilize the resource but also ensure it is migration-friendly for those migrating from v4 to v5.

Thank you for continuing to raise issues. They make our provider stronger and help us build products that reflect your needs.

This release includes new features, new resources and data sources, bug fixes, updates to our Developer Documentation, and more.

Breaking Change

Please be aware that there are breaking changes for the cloudflare_api_token and cloudflare_account_token resources. These changes eliminate configuration drift caused by policy ordering differences in the Cloudflare API.

For more specific information about the changes or the actions required, please see the detailed Repository changelog ↗︎.

Features

…

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

AI Search kann login-geschützte Websites per Custom Headers crawlen

AI Search unterstützt jetzt benutzerdefinierte HTTP-Header beim Website-Crawling, sodass sich auch durch Authentifizierung geschützte Inhalte (etwa hinter Cloudflare Access) indexieren lassen, mit bis zu fünf Headern pro Website-Datenquelle.

AI Search now supports custom HTTP headers for website crawling, solving a common problem where valuable content behind authentication or access controls could not be indexed.

Previously, AI Search could only crawl publicly accessible pages, leaving knowledge bases, documentation, and other protected content out of your search results. With custom headers support, you can now include authentication credentials that allow the crawler to access this protected content.

This is particularly useful for indexing content like:

  • Internal documentation behind corporate login systems
  • Premium content that requires users to provide access to unlock
  • Sites protected by Cloudflare Access using service tokens

To add custom headers when creating an AI Search instance, select Parse options. In the Extra headers section, you can add up to five custom headers per Website data source.

Custom headers configuration in AI Search

For example, to crawl a site protected by Cloudflare Access, you can add service token credentials as custom headers:

CF-Access-Client-Id: your-token-id.access …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Email security: Spalte „Final Disposition“ wird zu „Status“

Für Kunden ohne PhishGuard heißt die Spalte Final Disposition im Tab Team Submissions künftig Status und zeigt die Werte Submitted, Accepted oder Rejected.

Adjustment to Final Disposition column

The Final Disposition column in Submissions > Team Submissions tab is changing for non-Phishguard customers.

What's Changing

  • Column will be called Status instead of Final Disposition
  • Column status values will now be: Submitted, Accepted or Rejected.

Next Steps

We will listen carefully to your feedback and continue to find comprehensive ways to communicate updates on your submissions. Your submissions will continue to be addressed at an even greater rate than before, fuelling faster and more accurate email security improvement.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Neue Navigation und Produkterfahrung in Cloudflare One

Das Zero Trust Dashboard erhält eine neu strukturierte Navigation mit geführter Einführung beim Login, zusammengelegten Seiten, Suche nach alten und neuen Namen sowie Einstellungen näher an den jeweiligen Tools.

The Zero Trust dashboard and navigation is receiving significant and exciting updates. The dashboard is being restructured to better support common tasks and workflows, and various pages have been moved and consolidated.

There is a new guided experience on login detailing the changes, and you can use the Zero Trust dashboard search to find product pages by both their new and old names, as well as your created resources. To replay the guided experience, you can find it in Overview > Get Started.

Cloudflare One Dash Changes

Notable changes

  • Product names have been removed from many top-level navigation items to help bring clarity to what they help you accomplish. For example, you can find Gateway policies under ‘Traffic policies' and CASB findings under ‘Cloud & SaaS findings.'
  • You can view all analytics, logs, and real-time monitoring tools from ‘Insights.'
  • ‘Networks' better maps the ways that your corporate network interacts with Cloudflare. Some pages like Tunnels, are now a tab rather than a full page as part of these changes. You can find them at Networks > Connectors.
  • Settings are now located closer to the tools and resources they impact. For example, this means you'll find your WARP configurations at Team & Resources > Devices. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Updates für DELMIA Apriso und PHP

Die WAF-Erkennung für die Authentifizierungsbypass-Schwachstelle CVE-2025-6205 in DELMIA Apriso wurde verbessert; zwei PHP-Wrapper-Injection-Regeln wurden deaktiviert.

This week highlights enhancements to detection signatures improving coverage for vulnerabilities in DELMIA Apriso, linked to CVE-2025-6205.

Key Findings

This vulnerability allows unauthenticated attackers to gain privileged access to the application. The latest update provides enhanced detection logic for resilient protection against exploitation attempts.

Impact

  • DELMIA Apriso (CVE-2025-6205): Exploitation could allow an unauthenticated remote attacker to bypass security checks by sending specially crafted requests to the application's message processor. This enables the creation of arbitrary employee accounts, which can be leveraged to modify system configurations and achieve full system compromise.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...d256f4bc

N/A

DELMIA Apriso - Auth Bypass - CVE:CVE-2025-6205

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...1a3e521e

N/A

PHP Wrapper Injection - Body

N/A

Disabled

Rule metadata description refined. Detection unchanged.

Cloudflare Managed Ruleset

...8f76bd74

N/A

PHP Wrapper Injection - URI

N/A

Disabled

Rule metadata description refined. Detection unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Access: SSH-CA direkt im Dashboard erzeugen

Das Zertifikat der Cloudflare Access SSH certificate authority lässt sich jetzt im Cloudflare One Dashboard unter Access controls > Service credentials erstellen und verwalten, statt wie bisher nur über die API.

SSH with Cloudflare Access for Infrastructure allows you to use short-lived SSH certificates to eliminate SSH key management and reduce security risks associated with lost or stolen keys.

Previously, users had to generate this certificate by using the Cloudflare API ↗︎ directly. With this update, you can now create and manage this certificate in the Cloudflare One dashboard ↗︎ from the Access controls > Service credentials page.

Navigate to Access controls and then Service credentials to see where you can generate an SSH CA

For more details, refer to Generate a Cloudflare SSH CA.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

CASB: Neuer wöchentlicher SaaS-Security-Digest

Die neue optionale Benachrichtigung CASB Weekly Digest sendet jeden Montag eine Zusammenfassung der API-CASB-Findings und des Integrationsstatus der Vorwoche und ist unter Manage Account > Notifications aktivierbar.

You can now stay on top of your SaaS security posture with the new CASB Weekly Digest notification. This opt-in email digest is delivered to your inbox every Monday morning and provides a high-level summary of your organization's Cloudflare API CASB findings from the previous week.

This allows security teams and IT administrators to get proactive, at-a-glance visibility into new risks and integration health without having to log in to the dashboard.

To opt in, navigate to Manage Account > Notifications in the Cloudflare dashboard to configure the CASB Weekly Digest alert type.

Key capabilities

  • At-a-glance summary — Review new high/critical findings, most frequent finding types, and new content exposures from the past 7 days.
  • Integration health — Instantly see the status of all your connected SaaS integrations (Healthy, Unhealthy, or Paused) to spot API connection issues.
  • Proactive alerting — The digest is sent automatically to all subscribed users every Monday morning.
  • Easy to configure — Users can opt in by enabling the notification in the Cloudflare dashboard under Manage Account > Notifications.

Learn more

The CASB Weekly Digest notification is available to all Cloudflare users today.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Log Explorer: Datumsfilter-Konsistenz behoben

Ein Fehler im Log Explorer wurde behoben, der zu Abweichungen zwischen benutzerdefinierten SQL-Datumsfeldern und der Datumsauswahl führte; die Filter stimmen jetzt überein.

We've resolved a bug in Log Explorer that caused inconsistencies between the custom SQL date field filters and the date picker dropdown. Previously, users attempting to filter logs based on a custom date field via a SQL query sometimes encountered unexpected results or mismatching dates when using the interactive date picker.

This fix ensures that the custom SQL date field filters now align correctly with the selection made in the date picker dropdown, providing a reliable and predictable filtering experience for your log data. This is particularly important for users creating custom log views based on time-sensitive fields.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Log Explorer unterstützt jetzt 14 neue Datensätze

Log Explorer unterstützt jetzt 14 zusätzliche Datensätze von Cloudflare-Produkten auf Zone- und Account-Ebene, darunter Dns_logs, Audit Logs und Network Analytics.

We've significantly enhanced Log Explorer by adding support for 14 additional Cloudflare product datasets.

This expansion enables Operations and Security Engineers to gain deeper visibility and telemetry across a wider range of Cloudflare services. By integrating these new datasets, users can now access full context to efficiently investigate security incidents, troubleshoot application performance issues, and correlate logged events across different layers (like application and network) within a single interface. This capability is crucial for a complete and cohesive understanding of event flows across your Cloudflare environment.

The newly supported datasets include:

Zone Level

  • Dns_logs
  • Nel_reports
  • Page_shield_events
  • Spectrum_events
  • Zaraz_events

Account Level

  • Audit Logs
  • Audit_logs_v2
  • Biso_user_actions
  • DNS firewall logs
  • Email_security_alerts
  • Magic Firewall IDS
  • Network Analytics
  • Sinkhole HTTP
  • ipsec_logs

Note

Auditlog and Auditlog_v2 datasets require audit-log.read permission for querying.

The biso_user_actions dataset requires either the Super Admin or ZT PII role for querying.

Example: Correlating logs

…

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

DEX: Vier neue Logpush-Datensätze für WARP und DEX

Vier neue Datensätze (DEX Application Tests, DEX Device State Events, WARP Config Changes, WARP Toggle Changes) lassen sich per Logpush an R2, einen Cloud-Bucket oder ein SIEM exportieren.

Digital Experience Monitoring (DEX) provides visibility into WARP device metrics, connectivity, and network performance across your Cloudflare SASE deployment.

We've released four new WARP and DEX device data sets that can be exported via Cloudflare Logpush. These Logpush data sets can be exported to R2, a cloud bucket, or a SIEM to build a customized logging and analytics experience.

  1. DEX Application Tests
  2. DEX Device State Events
  3. WARP Config Changes
  4. WARP Toggle Changes

To create a new DEX or WARP Logpush job, customers can go to the account level of the Cloudflare dashboard > Analytics & Logs > Logpush to get started.

DEX logpush job creation dashboard

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers Analytics Engine: Neue SQL-Aggregat- und Datumsfunktionen

Workers Analytics Engine bietet nun zusätzliche SQL-Funktionen, darunter die Aggregatfunktionen countIf(), sumIf() und avgIf() sowie zahlreiche Datums- und Zeitfunktionen wie toYear(), toStartOfDay() und toYYYYMM().

You can now perform more powerful queries directly in Workers Analytics Engine ↗︎ with a major expansion of our SQL function library.

Workers Analytics Engine allows you to ingest and store high-cardinality data at scale (such as custom analytics) and query your data through a simple SQL API.

Today, we've expanded Workers Analytics Engine's SQL capabilities with several new functions:

New aggregate functions: ↗︎

  • countIf() - count the number of rows which satisfy a provided condition
  • sumIf() - calculate a sum from rows which satisfy a provided condition
  • avgIf() - calculate an average from rows which satisfy a provided condition

New date and time functions: ↗︎

  • toYear()
  • toMonth()
  • toDayOfMonth()
  • toDayOfWeek()
  • toHour()
  • toMinute()
  • toSecond()
  • toStartOfYear()
  • toStartOfMonth()
  • toStartOfWeek()
  • toStartOfDay()
  • toStartOfHour()
  • toStartOfFifteenMinutes()
  • toStartOfTenMinutes()
  • toStartOfFiveMinutes()
  • toStartOfMinute()
  • today()
  • toYYYYMM()

Ready to get started?

…

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

API Shield erkennt BOLA-Angriffe automatisch

API Shield erkennt jetzt automatisch Broken Object Level Authorization (BOLA)-Angriffe auf verwaltete API-Endpunkte und zeigt Details in Sicherheitsübersicht, Endpunktdetails und Security Analytics an.

Now, API Shield automatically searches for and highlights Broken Object Level Authorization (BOLA) attacks on managed API endpoints. API Shield will highlight both BOLA enumeration attacks and BOLA pollution attacks, telling you what was attacked, by who, and for how long.

You can find these attacks three different ways: Security Overview, Endpoint details, or Security Analytics. If these attacks are not found on your managed API endpoints, there will not be an overview card or security analytics suspicious activity card.

On the Security Overview card, select the suggestion > View details to review the top attacked API endpoints, endpoint details, and the attack summary: BOLA attack Overview card BOLA attack Overview drawer

From the endpoint details, you can select View attack to find details about the BOLA attacker’s sessions.

BOLA attack endpoint details

From here, select View in Analytics to observe attacker traffic over time for the last seven days. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für Windows 2025.9.558.0 (GA)

Der Windows WARP client 2025.9.558.0 ist als GA-Release verfügbar und bringt Path MTU Discovery (PMTUD), eine Verbindungsstatusmeldung in der GUI bei instabilem Netzwerk sowie Korrekturen unter anderem zu Global WARP override und zur Löschung von Registrierungen.

A new GA release for the Windows WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features including Path Maximum Transmission Unit Discovery (PMTUD). When PMTUD is enabled, the client will dynamically adjust packet sizing to optimize connection performance. There is also a new connection status message in the GUI to inform users that the local network connection may be unstable. This will make it easier to diagnose connectivity issues.

Changes and improvements

  • Fixed an inconsistency with Global WARP override settings in multi-user environments when switching between users.
  • The GUI now displays the health of the tunnel and DNS connections by showing a connection status message when the network may be unstable. This will make it easier to diagnose connectivity issues.
  • Fixed an issue where deleting a registration was erroneously reported as having failed. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für macOS 2025.9.558.0 (GA)

Der macOS WARP client 2025.9.558.0 ist als GA-Release verfügbar und bringt Path MTU Discovery (PMTUD), eine Verbindungsstatusmeldung in der GUI bei instabilem Netzwerk sowie eine Korrektur bei fälschlich als fehlgeschlagen gemeldeten Registrierungslöschungen.

A new GA release for the macOS WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features including Path Maximum Transmission Unit Discovery (PMTUD). When PMTUD is enabled, the client will dynamically adjust packet sizing to optimize connection performance. There is also a new connection status message in the GUI to inform users that the local network connection may be unstable. This will make it easier to diagnose connectivity issues.

Changes and improvements

  • The GUI now displays the health of the tunnel and DNS connections by showing a connection status message when the network may be unstable. This will make it easier to diagnose connectivity issues.
  • Fixed an issue where deleting a registration was erroneously reported as having failed. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für Linux 2025.9.558.0 (GA)

Der Linux WARP client 2025.9.558.0 ist als GA-Release verfügbar und bringt Path MTU Discovery (PMTUD), eine Verbindungsstatusmeldung in der GUI bei instabilem Netzwerk sowie eine Korrektur bei Registrierungslöschungen; der öffentliche Schlüssel für Linux-Pakete muss ggf. aktualisiert werden.

A new GA release for the Linux WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features including Path Maximum Transmission Unit Discovery (PMTUD). When PMTUD is enabled, the client will dynamically adjust packet sizing to optimize connection performance. There is also a new connection status message in the GUI to inform users that the local network connection may be unstable. This will make it easier to diagnose connectivity issues.

WARP client version 2025.8.779.0 introduced an updated public key for Linux packages. The public key must be updated if it was installed before September 12, 2025 to ensure the repository remains functional after December 4, 2025. Instructions to make this update are available at pkg.cloudflareclient.com.

Changes and improvements

  • The GUI now displays the health of the tunnel and DNS connections by showing a connection status message when the network may be unstable. This will make it easier to diagnose connectivity issues.
  • Fixed an issue where deleting a registration was erroneously reported as having failed. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

cloudflared: Befehl proxy-dns entfällt ab 2. Februar 2026

Ab dem 2. Februar 2026 wird der Befehl cloudflared proxy-dns aus allen neuen cloudflared-Releases entfernt, um eine Schwachstelle in einer DNS-Bibliothek zu beheben, während frühere Versionen weiterlaufen und andere Funktionen wie Cloudflare Tunnel nicht betroffen sind.

Starting February 2, 2026, the cloudflared proxy-dns command will be removed from all new cloudflared releases.

This change is being made to enhance security and address a potential vulnerability in an underlying DNS library. This vulnerability is specific to the proxy-dns command and does not affect any other cloudflared features, such as the core Cloudflare Tunnel service.

The proxy-dns command, which runs a client-side DNS-over-HTTPS (DoH) proxy, has been an officially undocumented feature for several years. This functionality is fully and securely supported by our actively developed products.

Versions of cloudflared released before this date will not be affected and will continue to operate. However, note that our official support policy for any cloudflared release is one year from its release date.

Migration paths

…

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

SQL-Fenster in Log Explorer ist jetzt in der Größe veränderbar

Das Fenster für benutzerdefinierte SQL-Abfragen in Log Explorer lässt sich jetzt in der Höhe anpassen, um längere Abfragen besser anzuzeigen.

We're excited to announce a quality-of-life improvement for Log Explorer users. You can now resize the custom SQL query window to accommodate longer and more complex queries.

Previously, if you were writing a long custom SQL query, the fixed-size window required excessive scrolling to view the full query. This update allows you to easily drag the bottom edge of the query window to make it taller. This means you can view your entire custom query at once, improving the efficiency and experience of writing and debugging complex queries.

To learn more and get started, refer to the Log Explorer documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Logpush Health Dashboards bieten Echtzeit-Einblicke

Logpush Health Dashboards bieten Echtzeit-Überblick über Status, Zuverlässigkeit und Leistung von Logpush-Jobs, aufgeteilt in Upload Health und Upload Reliability.

We’re excited to introduce Logpush Health Dashboards, giving customers real-time visibility into the status, reliability, and performance of their Logpush jobs. Health dashboards make it easier to detect delivery issues, monitor job stability, and track performance across destinations. The dashboards are divided into two sections:

  • Upload Health: See how much data was successfully uploaded, where drops occurred, and how your jobs are performing overall. This includes data completeness, success rate, and upload volume.

  • Upload Reliability – Diagnose issues impacting stability, retries, or latency, and monitor key metrics such as retry counts, upload duration, and destination availability.

Health Dashboard

Health Dashboards can be accessed from the Logpush page in the Cloudflare dashboard at the account or zone level, under the Health tab. For more details, refer to our Logpush Health Dashboards documentation, which includes a comprehensive troubleshooting guide to help interpret and resolve common issues.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

cloudflared proxy-dns-Befehl wird entfernt

Ab dem 2. Februar 2026 wird der Befehl cloudflared proxy-dns aus allen neuen cloudflared-Versionen entfernt, um eine Sicherheitslücke in einer DNS-Bibliothek zu schließen.

Starting February 2, 2026, the cloudflared proxy-dns command will be removed from all new cloudflared releases.

This change is being made to enhance security and address a potential vulnerability in an underlying DNS library. This vulnerability is specific to the proxy-dns command and does not affect any other cloudflared features, such as the core Cloudflare Tunnel service.

The proxy-dns command, which runs a client-side DNS-over-HTTPS (DoH) proxy, has been an officially undocumented feature for several years. This functionality is fully and securely supported by our actively developed products.

Versions of cloudflared released before this date will not be affected and will continue to operate. However, note that our official support policy for any cloudflared release is one year from its release date.

Migration paths

…

Originalquelle(öffnet in neuem Tab)Problem melden