Cloudflare logo

Cloudflare

Cloudflare general updates

Changelog

RSS
Cloudflare
Cloudflare Radar adds ASPA monitoring to detect BGP route leaks in real time//Cloudflare has introduced ASPA (Autonomous System Provider Authorization) deployment monitoring to Cloudflare Radar, enabling operators to track and verify the path Internet traffic takes across networks. ASPA builds on RPKI to detect route leaks—misdirected traffic caused by configuration errors or malicious actions—by cryptographically validating the chain of authorized providers in the AS path.
featuresecurityplatform
Cloudflare
Cloudflare Radar adds RPKI ASPA deployment tracking with new API endpoints//Cloudflare Radar now provides visibility into Autonomous System Provider Authorization (ASPA) adoption across the global routing ecosystem. The update includes three new API endpoints for retrieving ASPA snapshots, changes, and timeseries data, plus new dashboard widgets for tracking ASPA deployment trends globally and by region.
featureapiplatform
Cloudflare
Cloudflare Stream adds ability to disable and enable live inputs//Cloudflare Stream now allows developers to disable live inputs to reject incoming RTMPS and SRT connections, giving more control over broadcasts. The feature can be toggled via API or Dashboard, enabling temporary pauses, programmatic broadcast termination, and prevention of new streams on specific inputs.
featureapi
Cloudflare
Cloudflare One becomes first SASE platform with post-quantum encryption across all components//Cloudflare One now offers post-quantum hybrid ML-KEM encryption across its entire Secure Access Service Edge platform, including Secure Web Gateway, Zero Trust, and Wide Area Network services. The expansion covers Cloudflare IPsec (in closed beta) and Cloudflare One Appliance (generally available), enabling organizations to secure their enterprise network traffic against future quantum threats ahead of NIST's 2030 cryptographic transition deadline.
releasesecurityfeatureplatform
Cloudflare
Cloudflare Security Center adds saved views for Threat Events dashboard//Cloudflare Security Center now lets users save custom dashboard configurations for Threat Events, enabling analysts to instantly access pre-filtered views without manual reconfiguration. The feature supports complex filtering scenarios like industry-specific attacks and geographic filtering, improving workflow efficiency for Cloudforce One subscribers.
featuresecurityplatform
Cloudflare
Cloudflare adds saved views to Security Center's Threat Events dashboard//Cloudflare Security Center now lets users create and save custom filtered views of the Threat Events dashboard, enabling analysts to instantly return to specific configurations like industry-specific attack patterns or regional data flows. The feature eliminates repetitive manual filter reapplication and helps teams maintain consistent threat intelligence views.
featuresecurity
Cloudflare
Cloudflare launches MCP server using Code Mode, reducing API context requirements by 99.9%//Cloudflare introduced a new Model Context Protocol (MCP) server that provides access to the entire Cloudflare API using just two tools and consuming only ~1,000 tokens. The approach, called Code Mode, allows AI agents to write JavaScript code against a typed SDK to explore and execute API operations, reducing token usage from 1.17M to 1K compared to traditional MCP implementations.
integrationapifeaturesdkopen-source
Cloudflare
Cloudflare Tunnel now available in main Dashboard with full lifecycle management//Cloudflare Tunnel management is now integrated into the main Cloudflare Dashboard, eliminating the need to switch between interfaces. The new experience provides complete tunnel lifecycle management, native integrations with DNS and Workers VPC, real-time health monitoring, and a unified routing map for all ingress routes.
featureplatformintegration
Cloudflare
Cloudflare Tunnel management now available in core dashboard//Cloudflare Tunnel is now accessible directly from the main Cloudflare Dashboard under Networking > Tunnels, enabling developers to create, configure, and monitor tunnels in one place. The new interface includes full lifecycle management, native integrations with DNS and Workers VPC, and a unified routing map for managing all ingress routes.
featureplatformintegration
Cloudflare
Cloudflare improves AI Gateway and Workers AI dashboard with better navigation and onboarding//Cloudflare has rolled out a series of dashboard improvements for AI Gateway and Workers AI, including a dedicated top-level AI section in the sidebar, streamlined onboarding with OpenAI-compatible endpoints, and enhancements to dynamic routing and observability. The update also brings accessibility improvements to keyboard navigation and filtering components.
featureplatformintegration
Cloudflare
Cloudflare adds threat visualization to Cloudforce One dashboard with Sankey diagrams//Cloudflare Security Center now includes dynamic visualizations for Cloudforce One Threat Events, featuring Sankey diagrams to trace attack flows geographically and charts showing campaign distribution over time. Subscribers can explore these new analytics views to better understand emerging threat patterns and drill down into specific attack vectors.
featuresecurityplatform
Cloudflare
Cloudflare DEX now complies with EU Customer Metadata Boundary settings//Digital Experience Monitoring (DEX) now fully supports Cloudflare's Customer Metadata Boundary (CMB) for the EU, ensuring DEX logs remain within EU data residency requirements when enabled. Users can export DEX data via LogPush to build custom analytics dashboards while maintaining compliance.
featureapiplatformsecurity
Cloudflare
Cloudflare Containers and Sandboxes gain Docker-in-Docker support//Cloudflare's Containers and Sandboxes services now support Docker-in-Docker functionality, enabling developers to run full containerized environments within sandboxes. This feature is particularly useful for CI/CD workflows, testing container images, and running isolated development environments.
featureplatformsdk
Cloudflare
Cloudflare Access streamlines clientless app access with new policy setting//Cloudflare has introduced an "Allow clientless access" setting that simplifies how organizations grant browser-based access to private self-hosted applications without requiring a device client. Users can now manage this capability directly within their Access application policies rather than creating separate bookmark applications.
featureapi
Cloudflare
Cloudflare Access now supports policies for bookmark applications//Cloudflare has extended Access policies to bookmark applications, allowing administrators to control which users see specific bookmarks in the App Launcher based on identity, device posture, and other policy rules. This replaces the previous behavior where all bookmarks were visible to everyone in the organization.
featureapi
Cloudflare
Cloudflare Access now supports policies for bookmark applications//Cloudflare has added Access policy support to bookmark applications, allowing administrators to control which users see specific bookmarks in the App Launcher based on identity, device posture, and group membership. Previously, all bookmarks were visible to all users; now they can be restricted to specific audiences while maintaining backward compatibility for unpolicied bookmarks.
featureapiplatform
Cloudflare
Cloudflare Access adds streamlined clientless access for private applications//Cloudflare has introduced a new "Allow clientless access" setting that simplifies how organizations grant access to private self-hosted applications without requiring a device client. Users who pass Access policies can now directly access these applications through their App Launcher, with automatic handling of the prefixed Clientless Web Isolation URL.
featureplatform
Cloudflare
Cloudflare open-sources ecdysis, a Rust library for zero-downtime service restarts//After five years of production use, Cloudflare has open-sourced ecdysis, a Rust library that enables graceful restarts of network services without dropping connections or refusing requests. The library implements a fork-based approach pioneered by NGINX, allowing parent and child processes to seamlessly share socket file descriptors during upgrades.
open-sourcefeaturesdkrelease
Cloudflare
Cloudflare Python SDK v5.0.0-beta.1 introduces major breaking changes and 40+ new API resources//Cloudflare released the first beta version of Python SDK v5.0.0, featuring significant breaking changes driven by OpenAPI schema improvements and code generation updates. The release adds over 40 new API resources including AI-powered features, brand protection tools, D1 database management, and Real-time Kit integrations, alongside general fixes for type inference, request handling, and response parsing.
sdkreleasebreaking-changeapifeature
Cloudflare
Cloudflare adds GLM-4.7-Flash model and TanStack AI support to Workers AI//Cloudflare has launched GLM-4.7-Flash, a multilingual AI model with 131K token context and multi-turn tool calling, alongside new TanStack AI adapters and enhanced Vercel AI SDK support. The updates enable developers to build and run AI agents entirely at the edge with expanded capabilities including transcription, speech synthesis, and document reranking.
releasefeaturemodelapisdkintegration
Cloudflare
Cloudflare enhances logo matching with configurable thresholds starting at 75%//Cloudflare's Security Center now offers enhanced logo matching capabilities for brand protection, enabling detection of subtle brand asset variations and impersonations. The update introduces configurable match thresholds, visual match scores with color-coded severity indicators, and direct logo previews in the dashboard.
featuresecurity
Cloudflare
Cloudflare WAN dashboard now displays Anycast IPs for tunnels//Cloudflare WAN customers can now view their Anycast IP addresses directly in the dashboard when configuring IPsec or GRE tunnels. This replaces the previous workflow requiring manual API calls or onboarding retrieval, streamlining tunnel setup and reducing configuration errors.
featureplatform
Cloudflare
Cloudflare disables fake Google Bot detection rule in WAF//Cloudflare has disabled the "Anomaly:Header:User-Agent - Fake Google Bot" rule in its Managed Ruleset, changing it from a blocking action to disabled status. This prevents the WAF from blocking requests that appear to be spoofed Google Bot traffic.
bugfixsecurityplatform
Cloudflare
Cloudflare WAF adds detection rules for Zimbra and Vite vulnerabilities//Cloudflare is deploying two new security detection rules to its Web Application Firewall on February 16, 2026. The new rules target vulnerabilities in Zimbra (local file inclusion) and Vite (WASM import path traversal), launching initially in log mode to detect threats without blocking traffic.
securityfeaturerelease
Cloudflare
Cloudflare launches R2 Local Uploads in beta; up to 75% faster cross-region uploads//Cloudflare has released Local Uploads for R2 object storage, an open beta feature that writes upload data to storage near the client first, then replicates asynchronously to the bucket's primary location. The feature reduces upload latency by up to 75% for cross-region uploads while maintaining strong consistency and immediate data accessibility.
releasefeatureperformance
Cloudflare
Cloudflare Email Security improves monitoring dashboard with search, accessibility enhancements//Cloudflare has updated its Email Security monitoring page with improved visual layouts, enhanced accessibility features, and new search functionality across widgets. The update includes stacked bar charts for better data visualization, widget search for Policies and Submitters, and granular data breakdowns by month and threat type across all Email Security tiers.
featureplatform