C

Cloudflare changelogs | Application security

Cloudflare changelogs for Application security products

WAF - Leaked credentials detection now scans Authorization headers

<p><a href="https://developers.cloudflare.com/waf/detections/leaked-credentials/">Leaked credentials detection</a> now scans the <code>Authorization</code> request header for Basic Authentication credentials. Previously, the detection only inspected request bodies, query strings, and headers for well-known web applications or custom detection locations, which meant credentials sent through HTTP Basic Authentication were not covered by default.</p> <p>This new default scan location decodes the <code>Authorization: Basic &lt;credentials&gt;</code> header and compares the extracted username and password against Cloudflare's database of leaked credentials, the same way as other default scan locations. Matches populate the existing <a href="https://developers.cloudflare.com/waf/detections/leaked-credentials/#leaked-credentials-fields">leaked credentials fields</a>, such as <code>cf.waf.credential_check.password_leaked</code>, and trigger the <a href="https://developers.cloudflare.com/rules/transform/managed-transforms/reference/#add-leaked-credentials-checks-header"><code>Exposed-Credential-Check</code> managed transform header</a> if configured, so you can reuse existing <a href="https://developers.cloudflare.com/waf/custom-rules/">custom rules</a> and <a href="https://developers.cloudflare.com/waf/rate-limiting-rules/">rate limiting rules</a> without changes.</p> <p>This change was applied automatically for zones with leaked credentials detection enabled. No configuration changes are required.</p> <p>For more information, refer to <a href="https://developers.cloudflare.com/waf/detections/leaked-credentials/">Leaked credentials detection</a>.</p>

2026/8/20
阅读更多

WAF - WAF Release - 2026-08-17

<p>This release updates WordPress remote code execution rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify CVE-2026-65640.</p> <p><strong>Key Findings</strong></p> <ul> <li>CVE-2026-65640: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.</li> </ul> <p><strong>Impact</strong></p> <p>The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.</p> <table style="width: 100%"><thead><tr><th>Ruleset</th><th>Rule ID</th><th>Legacy Rule ID</th><th>Description</th><th>Previous Action</th><th>New Action</th><th>Comments</th></tr></thead><tbody><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="dcf635ab2e744e1a994443973590a4ad"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...3590a4ad</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script></td><td>N/A</td><td>Wordpress - Remote Code Execution - CVE:CVE-2026-65640</td><td>Block</td><td>N/A</td><td>Rule metadata description refined. Detection unchanged.</td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="6ad9f2049b094c608be0f8adcfe1a93c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...cfe1a93c</span></button></rule-id></td><td>N/A</td><td>Wordpress - Remote Code Execution - CVE:CVE-2026-65640</td><td>Block</td><td>N/A</td><td>Rule metadata description refined. Detection unchanged.</td></tr></tbody></table>

2026/8/17
阅读更多

WAF - WAF Release - Scheduled changes for 2026-08-24

<table style="width: 100%"><thead><tr><th>Announcement Date</th><th>Release Date</th><th>Release Behavior</th><th>Legacy Rule ID</th><th>Rule ID</th><th>Description</th><th>Comments</th></tr></thead><tbody><tr><td>2026-08-17</td><td>2026-08-24</td><td>Log</td><td>N/A</td><td><rule-id id="a80f214f0947435dabb2ba2d1489d892"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...1489d892</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script></td><td>HTTP/2 Request Smuggling - Request Body Anomaly</td><td><p>This is a new detection.</p></td></tr><tr><td>2026-08-17</td><td>2026-08-24</td><td>Log</td><td>N/A</td><td><rule-id id="58a184412d2b4113bca6379b20646260"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...20646260</span></button></rule-id></td><td>XSS - JavaScript Event Handler Coercion - Headers</td><td><p>This is a new detection.</p></td></tr><tr><td>2026-08-17</td><td>2026-08-24</td><td>Log</td><td>N/A</td><td><rule-id id="e79cb939d6aa41db984e6db3d706d517"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...d706d517</span></button></rule-id></td><td>XSS - JavaScript Event Handler Coercion - Body</td><td><p>This is a new detection.</p></td></tr><tr><td>2026-08-17</td><td>2026-08-24</td><td>Log</td><td>N/A</td><td><rule-id id="7e3249c7a5d8469697478746660886c8"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...660886c8</span></button></rule-id></td><td>XSS - JavaScript Event Handler Coercion - URI</td><td><p>This is a new detection.</p></td></tr><tr><td>2026-08-17</td><td>2026-08-24</td><td>Log</td><td>N/A</td><td><rule-id id="d34bc5db8cbc4e18a44ed115c293b926"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...c293b926</span></button></rule-id></td><td>XSS, HTML Injection - Script Tag - Beta</td><td><p>This rule will be merged into the original rule "XSS, HTML Injection - Script Tag" (ID: <rule-id id="9c8dda9708cc4452ac76e7be7b58420b"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...7b58420b</span></button></rule-id>).</p></td></tr></tbody></table>

2026/8/17
阅读更多

WAF - WAF Release - 2026-08-11

<p>This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections.</p> <p><strong>Key Findings</strong></p> <ul> <li>A new detection provides protection against vBulletin CVE-2026-61511.</li> <li>Two existing detections have been improved to strengthen coverage.</li> </ul> <p><strong>Impact</strong></p> <p>Successful exploitation of CVE-2026-61511 may lead to remote code execution on affected vBulletin systems, potentially resulting in unauthorized access, data exposure, service disruption, and broader compromise of the hosting environment. Administrators are strongly encouraged to apply vendor updates and recommended mitigations.</p> <table style="width: 100%"><thead><tr><th>Ruleset</th><th>Rule ID</th><th>Legacy Rule ID</th><th>Description</th><th>Previous Action</th><th>New Action</th><th>Comments</th></tr></thead><tbody><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="1b0775f0f092483387cfb23f94f3006b"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...94f3006b</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script></td><td>N/A</td><td>vBulletin - Remote Code Execution - CVE:CVE-2026-61511</td><td>Log</td><td>Block</td><td>This is a new detection.</td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="784d3824b6cf419db6af0b64098b749e"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...098b749e</span></button></rule-id></td><td>N/A</td><td>Version Control - Information Disclosure - Beta</td><td>Log</td><td>Block</td><td>This rule is merged into the original rule "Version Control - Information Disclosure" (ID: <rule-id id="23548ee2b36547a1be09bb2c0550c529"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...0550c529</span></button></rule-id>)</td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="a561c9138b46470ca6db96edd56225d8"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...d56225d8</span></button></rule-id></td><td>N/A</td><td>vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132 - Beta</td><td>Log</td><td>Block</td><td>This rule is merged into the original rule "vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132" (ID: <rule-id id="5137834eb8634842852273a08fe9f1c7"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...8fe9f1c7</span></button></rule-id>)</td></tr></tbody></table>

2026/8/11
阅读更多

Turnstile - Turnstile Spin is now generally available

<p><a href="https://developers.cloudflare.com/turnstile/spin/">Turnstile Spin</a> is now generally available with three setup paths for creating a Turnstile widget and wiring canonical server-side siteverify into your existing backend. Start in the dashboard, with Wrangler, or from your AI coding agent. All three paths create the same widget. You can complete the integration by hand or have your agent embed the widget, wire siteverify, and validate it.</p> <div tabindex="-1" class="heading-wrapper level-h4"><h4 id="server-side-verification">Server-side verification</h4><a class="anchor-link" href="#server-side-verification"><span aria-hidden="true" class="anchor-icon"><svg width="16" height="16" viewBox="0 0 24 24"><path fill="currentcolor" d="m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z"></path></svg></span></a></div> <p>Turnstile setup has two parts: embed the widget in your frontend, then call siteverify from your backend. Without the second part, the widget appears on the page but does not protect the request.</p> <ul> <li>The skill includes insertion snippets for Next.js (App Router and Pages Router), Astro, SvelteKit, Hugo, and vanilla HTML. For other frameworks, the agent proposes a generic pattern and asks you to confirm it first.</li> <li>The Turnstile dashboard flags existing widgets with no matching siteverify traffic. Select <strong>Fix with Spin</strong> to copy a prompt that guides your agent through wiring siteverify into your backend.</li> <li>Before finishing, the agent runs a real Turnstile token through your protected endpoint, checks that it passes, then replays the token to confirm the endpoint rejects it on the second try. If a check fails, the agent stops and shows you where.</li> </ul> <div tabindex="-1" class="heading-wrapper level-h4"><h4 id="run-spin">Run Spin</h4><a class="anchor-link" href="#run-spin"><span aria-hidden="true" class="anchor-icon"><svg width="16" height="16" viewBox="0 0 24 24"><path fill="currentcolor" d="m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z"></path></svg></span></a></div> <p>You can run Spin three ways:</p> <ul> <li>In the <strong>Turnstile dashboard</strong>, select <strong>Set up with Spin</strong>, enter your domains, then select <strong>Set up</strong>. Spin creates the widget and returns the sitekey, secret, and a prompt for your agent.</li> <li>From the <code>Wrangler CLI</code>, run <a href="https://developers.cloudflare.com/turnstile/spin/#set-up-from-the-wrangler-cli"><code>wrangler turnstile widget create</code></a>. Wrangler prints the sitekey and secret. You wire the frontend and siteverify by hand.</li> <li>From your <strong>AI coding agent</strong>, paste the <a href="https://developers.cloudflare.com/turnstile/spin/#set-up-from-an-ai-coding-agent">Spin prompt</a> into Claude Code, Cursor, Codex, OpenCode, or GitHub Copilot Chat. Your agent fetches the skill, creates the widget, then embeds it and wires siteverify.</li> </ul> <p>To get started, refer to the <a href="https://developers.cloudflare.com/turnstile/spin/">Turnstile Spin documentation</a>.</p>

2026/8/10
阅读更多

WAF - WAF Release - 2026-08-07

<p>This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule.</p> <p><strong>Key Findings</strong></p> <ul> <li>CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen. Exploitation requires social engineering and explicit interaction by the target user. Under additional conditions, it may be escalated to remote code execution.</li> </ul> <p><strong>Impact</strong></p> <p>The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.</p> <table style="width: 100%"><thead><tr><th>Ruleset</th><th>Rule ID</th><th>Legacy Rule ID</th><th>Description</th><th>Previous Action</th><th>New Action</th><th>Comments</th></tr></thead><tbody><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="d3852d0891634686a46114069c6dff1c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...9c6dff1c</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script></td><td>N/A</td><td>Wordpress - XSS - CVE:CVE-2026-64638</td><td>Block</td><td>N/A</td><td>Rule metadata description refined. Detection unchanged.</td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="5bdf578fff504b8cbe3b7f699ab5ed95"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...9ab5ed95</span></button></rule-id></td><td>N/A</td><td>Wordpress - XSS - CVE:CVE-2026-64638</td><td>Block</td><td>N/A</td><td>Rule metadata description refined. Detection unchanged.</td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="95a84ab1645a49c685648c17761e7a4c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...761e7a4c</span></button></rule-id></td><td>N/A</td><td>Command Injection - Obfuscation</td><td>Block</td><td>Disabled</td><td>Detection logic has been deprecated</td></tr></tbody></table>

2026/8/7
阅读更多

WAF - WAF Release - 2026-08-04

<p>This release introduces new rules and updates Microsoft SharePoint RCE alongside enhanced SSRF cloud protection rule actions.</p> <p><strong>Key Findings</strong></p> <ul> <li>CVE-2026-50522: An insecure deserialization vulnerability in Microsoft SharePoint Server. This may allow an unauthenticated attacker to execute arbitrary code using crafted requests.</li> <li>CVE-2026-66066: An improper input processing vulnerability in Ruby on Rails Active Storage image variant transformations. This may allow an unauthenticated attacker to perform arbitrary file reads and achieve Remote Code Execution (RCE) using maliciously crafted payload requests.</li> <li>Generic Cloud Protections: Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications.</li> </ul> <table style="width: 100%"><thead><tr><th>Ruleset</th><th>Rule ID</th><th>Legacy Rule ID</th><th>Description</th><th>Previous Action</th><th>New Action</th><th>Comments</th></tr></thead><tbody><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="91aee93c31944828bf86f068052b07cf"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...052b07cf</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script></td><td>N/A</td><td>Microsoft SharePoint - Remote Code Execution - CVE:CVE-2026-50522</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="89d0243997d24c6ea1d610a23a5b40d6"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...3a5b40d6</span></button></rule-id></td><td>N/A</td><td>Rails - Arbitrary File Read &amp; RCE - CVE:CVE-2026-66066</td><td>Block</td><td>Block</td><td><p>This was labeled as File Upload - RCE.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="ae40661b4ef24f9c8abd98338242627b"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...8242627b</span></button></rule-id></td><td>N/A</td><td>SSRF - Local</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="98bfd6bb46074d5b8d1c4b39743a63ec"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...743a63ec</span></button></rule-id></td><td>N/A</td><td>SSRF - Local - 2 - Beta</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="54e1733b10da4a599e06c6fbc2e84e2d"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...c2e84e2d</span></button></rule-id></td><td>N/A</td><td>SSRF - Cloud - Beta</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="ecd26d61a75e46f6a4449a06ab8af26f"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...ab8af26f</span></button></rule-id></td><td>N/A</td><td>SSRF - Cloud - 2 - Beta</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="281a1b7086b84db7a695220725ba9d7c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...25ba9d7c</span></button></rule-id></td><td>N/A</td><td>SSRF - Cloud</td><td>Disabled</td><td>Block</td><td><p>We are changing the action for this rule from Disabled to BLOCK</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="158177dec2504acdba1f2da201a076eb"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...01a076eb</span></button></rule-id></td><td>N/A</td><td>SSRF - Local - Beta</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr></tbody></table>

2026/8/4
阅读更多

WAF - WAF Release - 2026-07-29

<p>This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Nuxt Server Island components and Alibaba Fastjson deserialization routines, alongside enhanced protections for cloud metadata Server-Side Request Forgery (SSRF) and obfuscated command injection attempts.</p> <p><strong>Key Findings</strong></p> <ul> <li> <p>Nuxt Server Island - RCE(GHSA-9473-5f9j-94wq): An unauthenticated vulnerability in Nuxt Server Islands where remote attackers can supply arbitrary component names or props to endpoints. Manipulating these parameters allows unauthenticated component Remote Code Execution (RCE) on the server.</p> </li> <li> <p>Alibaba Fastjson JSONType Remote Code Execution: A unauthenticated remote code execution vulnerability in Alibaba Fastjson (≤ 1.2.83) during JSON deserialization. Under default configurations, attackers can execute arbitrary system commands, bypassing traditional classpath and gadget-based defenses.</p> </li> <li> <p>Generic Protections (SSRF &amp; Command Injection): Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications, alongside new rules targeting obfuscated command injection patterns across request parameters.</p> </li> </ul> <table style="width: 100%"><thead><tr><th>Ruleset</th><th>Rule ID</th><th>Legacy Rule ID</th><th>Description</th><th>Previous Action</th><th>New Action</th><th>Comments</th></tr></thead><tbody><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="54e1733b10da4a599e06c6fbc2e84e2d"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...c2e84e2d</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script></td><td>N/A</td><td>SSRF - Cloud - Beta</td><td>Log</td><td>Block</td><td><p>This is an improved detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="95a84ab1645a49c685648c17761e7a4c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...761e7a4c</span></button></rule-id></td><td>N/A</td><td>Command Injection - Obfuscation</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="58df9693db4d454a8764fcda7347c892"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...7347c892</span></button></rule-id></td><td>N/A</td><td>Alibaba Fastjson JSONType Remote Code Execution - Body</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="6159ead63d284147943dc5a18ec012ea"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...8ec012ea</span></button></rule-id></td><td>N/A</td><td>Nuxt Server Island - RCE</td><td>N/A</td><td>Block</td><td><p>This is a new detection.This was labeled as Generic Rules - RCE.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="dcf635ab2e744e1a994443973590a4ad"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...3590a4ad</span></button></rule-id></td><td>N/A</td><td>Generic Rules - RCE</td><td>N/A</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="d3852d0891634686a46114069c6dff1c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...9c6dff1c</span></button></rule-id></td><td>N/A</td><td>Generic Rules - XSS</td><td>N/A</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="89d0243997d24c6ea1d610a23a5b40d6"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...3a5b40d6</span></button></rule-id></td><td>N/A</td><td>File Upload - RCE</td><td>N/A</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="6ad9f2049b094c608be0f8adcfe1a93c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...cfe1a93c</span></button></rule-id></td><td>N/A</td><td>Generic Rules - RCE</td><td>N/A</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="5bdf578fff504b8cbe3b7f699ab5ed95"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...9ab5ed95</span></button></rule-id></td><td>N/A</td><td>Generic Rules - XSS</td><td>N/A</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="7ecac499d14a4750aa58c1e21b7f9c67"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...1b7f9c67</span></button></rule-id></td><td>N/A</td><td>File Upload - RCE</td><td>N/A</td><td>Block</td><td><p>This is a new detection.</p></td></tr></tbody></table>

2026/7/29
阅读更多

WAF - WAF Release - 2026-07-21

<p>This release introduces new rules for vulnerabilities in Adobe ColdFusion, Next.js, WordPress alongside updates to existing rules thereby providing enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS).</p> <p><strong>WAF and framework adapter mitigations for Next.js vulnerabilities</strong></p> <p>Multiple <a href="https://nextjs.org/blog/july-2026-security-release" target="_blank" rel="noopener">security vulnerabilities<span class="external-link"> ↗</span></a> were disclosed and patched by the Next.js team through July 2026 security release. These include denial of service, middleware and proxy bypass, server-side request forgery, information disclosure, and cache poisoning across a range of severities.</p> <p>Several of the disclosed vulnerabilities are not possible to block at WAF layer,we strongly recommend updating your application and its dependencies immediately. Patched versions are available through v16.2.11 (Active LTS) and v15.5.21 (Maintenance LTS) to address these issues.</p> <table style="width: 100%"><thead><tr><th>Advisory</th><th>CVE</th><th>Severity</th><th>Issue</th><th>WAF Coverage</th></tr></thead><tbody><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj">Denial of Service in App Router using Server Actions</a></td><td>CVE-2026-64641</td><td>High</td><td><p>Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage. The CPU usage blocks processing of further requests in the same process, leading to Denial of Service.</p></td><td><p>WAF rule Next.js - DoS - CVE-2026-64641 (<rule-id id="b013b67c357547b4b866234390dcdb0a"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...90dcdb0a</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script>) has been deployed to provide coverage.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24">Middleware / Proxy bypass in App Router applications using Turbopack and single locale</a></td><td>CVE-2026-64642</td><td>High</td><td><p>Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales are vulnerable to a middleware/proxy bypass. Accordingly, any authentication or security checks that a middleware/proxy may perform are bypassed.</p></td><td><p>This is a middleware bypass that unfortunately cannot be covered through Cloudflare WAF signature engine.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4">Server-Side Request Forgery in rewrites via attacker-controlled destination hostname</a></td><td>CVE-2026-64645</td><td>High</td><td><p>A rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For rewrites, this behavior enables Server-Side Request Forgery (SSRF); for redirects, Open Redirect can be achieved.</p></td><td><p>Existing SSRF rules provide adequate coverage for this vulnerability, no tailored WAF rule was developed.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9x">Server-Side Request Forgery in Server Actions on custom servers</a></td><td>CVE-2026-64649</td><td>High</td><td><p>When a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker’s request to control Host-associated headers.</p></td><td><p>WAF rule Next.js - SSRF - CVE-2026-64649 (<rule-id id="7fe6d6f3df774ae2a0011f20930091a3"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...930091a3</span></button></rule-id>) has been deployed to provide coverage.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch">Denial of Service in the Image Optimization API using SVGs</a></td><td>CVE-2026-64644</td><td>Medium</td><td><p>When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, the images can cause CPU exhaustion in the /_next/image endpoint.</p></td><td><p>Malicious request is unfortunately indistinguishable from a legitimate image optimization request, so no WAF rule has been created to address this vulnerability.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3">Unbounded Server Action payload in Edge runtime</a></td><td>CVE-2026-64646</td><td>Medium</td><td><p>A crafted request can lead to memory consumption on Server Actions in the Edge runtime. Next.js applications which use App Router and have at least one Server Action are affected.</p></td><td><p>Unfortunately there is no one size fits all rule that can be deployed through WAF in lieu of custom bodySizeLimit configurations, so no WAF rule has been created to address this vulnerability.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp">Unauthenticated disclosure of internal Server Function endpoints</a></td><td>CVE-2026-64643</td><td>Medium</td><td><p>In Next.js applications using App Router, Server Actions (use server) or use cache endpoint IDs can be globally disclosed. An attacker can use this for reconnaissance and as part of a broader attack chain.</p></td><td><p>WAF rule Next.js - Information Disclosure - CVE-2026-64643 (<rule-id id="6c4135d4d9d745e4866ad83672952826"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...72952826</span></button></rule-id>) has been deployed to provide coverage.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742">Cache confusion of response bodies for requests with bodies</a></td><td>CVE-2026-64648</td><td>Medium</td><td><p>A server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. This only applies for fetch calls of the shape fetch(new Request(init), aDifferentInit)</p></td><td><p>This is an application logic bug that unfortunately cannot be covered through Cloudflare WAF signature engine.</p></td></tr><tr><td><a href="https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q">Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences</a></td><td>CVE-2026-64647</td><td>Medium</td><td><p>A server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. This only applies when receiving request bodies which contain invalid UTF-8 characters.</p></td><td><p>This is an application logic bug that unfortunately cannot be covered through Cloudflare WAF signature engine.</p></td></tr></tbody></table> <p><strong>Key Findings</strong></p> <ul> <li> <p>CVE-2026-48276: A path traversal vulnerability in Adobe ColdFusion file upload mechanisms allows unauthenticated attackers to write or upload files to arbitrary locations outside designated directories on the origin server.</p> </li> <li> <p>CVE-2026-48282: A path traversal vulnerability in Adobe ColdFusion enables unauthenticated attackers to manipulate directory sequences and access restricted system files on the host filesystem.</p> </li> <li> <p>CVE-2026-60137: An unauthenticated SQL injection vulnerability affecting WordPress. Threat actors exploit unsanitized input parameters to execute arbitrary SQL queries, leading to unauthorized database access, record manipulation, or data exfiltration.</p> </li> <li> <p>CVE-2026-63030: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.</p> </li> </ul> <table style="width: 100%"><thead><tr><th>Ruleset</th><th>Rule ID</th><th>Legacy Rule ID</th><th>Description</th><th>Previous Action</th><th>New Action</th><th>Comments</th></tr></thead><tbody><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="7fbdc9407bdb4a4eae2b3d91215e7d31"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...215e7d31</span></button></rule-id></td><td>N/A</td><td>SSRF - Restricted Protocol</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="6ca512d240d848d6a0c7ef42a935ee5d"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...a935ee5d</span></button></rule-id></td><td>N/A</td><td>SSRF - Obfuscated Host</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="a3fb0870c38440d8a9a0eba81b0230ac"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...1b0230ac</span></button></rule-id></td><td>N/A</td><td>LFI - Path Traversal</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="452a04be3f73458c863d8dae61349c8b"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...61349c8b</span></button></rule-id></td><td>N/A</td><td>Adobe ColdFusion - File Upload Path Traversal - CVE:CVE-2026-48276</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="a53a3fb491c64d74908081ee9cb61eac"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...9cb61eac</span></button></rule-id></td><td>N/A</td><td>Adobe ColdFusion - Path Traversal - CVE:CVE-2026-48282</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="d8b63828c2344d919b94d2594ac5e21f"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...4ac5e21f</span></button></rule-id></td><td>N/A</td><td>XSS — JS Bracket Concat Obfuscation - Body</td><td>Log</td><td>Disabled</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="264a83a764be428ca41d516ff31f5559"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...f31f5559</span></button></rule-id></td><td>N/A</td><td>XSS — JS Bracket Concat Obfuscation - Headers</td><td>Log</td><td>Disabled</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="4ba21a60837244029183b782987984fd"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...987984fd</span></button></rule-id></td><td>N/A</td><td>XSS — JS Bracket Concat Obfuscation - URI</td><td>Log</td><td>Block</td><td><p>This is a new detection.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="1c060d3a371549219ee290d7ed933fcc"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...ed933fcc</span></button></rule-id></td><td>N/A</td><td>Wordpress - SQL Injection - CVE:CVE-2026-60137</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - SQLi.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="7dfb2bd4708d4b88b9911dc0550664b6"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...550664b6</span></button></rule-id></td><td>N/A</td><td>Wordpress - Remote Code Execution - CVE:CVE-2026-63030</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - Unauthenticated RCE.</p></td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="db003b39b7774859a8d588ce33697a1a"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...33697a1a</span></button></rule-id></td><td>N/A</td><td>Wordpress - SQL Injection - CVE:CVE-2026-60137</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - SQLi.</p></td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="ebd3f2df15c74ddcbf6220c9b5ec246a"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...b5ec246a</span></button></rule-id></td><td>N/A</td><td>Wordpress - Remote Code Execution - CVE:CVE-2026-63030</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - Unauthenticated RCE.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="6c4135d4d9d745e4866ad83672952826"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...72952826</span></button></rule-id></td><td>N/A</td><td>Next.js - Information Disclosure - CVE-2026-64643</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - Information Disclosure.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="7fe6d6f3df774ae2a0011f20930091a3"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...930091a3</span></button></rule-id></td><td>N/A</td><td>Next.js - SSRF - CVE-2026-64649</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - Auth Bypass - 2.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="c4ca56c0a6a348299d5a93e663167195"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...63167195</span></button></rule-id></td><td>N/A</td><td>Next.js - Remote Code Execution - Cache Components</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - RCE.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="b013b67c357547b4b866234390dcdb0a"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...90dcdb0a</span></button></rule-id></td><td>N/A</td><td>Next.js - DoS - CVE-2026-64641</td><td>N/A</td><td>Block</td><td><p>This was labeled as Generic Rules - DoS.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="aa21c9b8b97743bfb217748b2049a60c"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...2049a60c</span></button></rule-id></td><td>N/A</td><td>Generic Rules - Command Execution - Body - Beta</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="e7ee67e824844754b513cdf3836855a4"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...836855a4</span></button></rule-id></td><td>N/A</td><td>Generic Rules - Command Execution - Header - Beta</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="5f2a6681a2b94442b23816286d060a0d"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...6d060a0d</span></button></rule-id></td><td>N/A</td><td>Generic Rules - Command Execution - URI - Beta</td><td>Disabled</td><td> - </td><td><p>This detection has been removed.</p></td></tr></tbody></table>

2026/7/21
阅读更多

WAF - WAF Release - 2026-07-17 - Emergency

<p>This emergency release adds a new managed rule to block active exploitation of a critical remote code execution (RCE) and SQL injection (SQLi) vulnerability found in popular web frameworks.</p> <p><strong>Key Findings</strong></p> <ul> <li> <p>Generic Frameworks - Unauthenticated RCE: Attackers can execute arbitrary system commands with web server privileges by sending malicious input containing invalid path sequences during request processing.</p> </li> <li> <p>Generic Frameworks - SQLi: Attackers can execute unauthorized database queries due to a failure to sanitize input values within request parameters.</p> </li> </ul> <table style="width: 100%"><thead><tr><th>Ruleset</th><th>Rule ID</th><th>Legacy Rule ID</th><th>Description</th><th>Previous Action</th><th>New Action</th><th>Comments</th></tr></thead><tbody><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="7dfb2bd4708d4b88b9911dc0550664b6"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...550664b6</span></button></rule-id><script type="module" src="https://developers.cloudflare.com/home/runner/work/cloudflare-docs/cloudflare-docs/src/components/cf/RuleID.astro?astro&type=script&index=0&lang.ts"></script></td><td>N/A</td><td>Generic Rules - Unauthenticated RCE</td><td>N/A</td><td>Block</td><td>This is a new detection.</td></tr><tr><td>Cloudflare Managed Ruleset</td><td><rule-id id="1c060d3a371549219ee290d7ed933fcc"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...ed933fcc</span></button></rule-id></td><td>N/A</td><td>Generic Rules - SQLi </td><td>N/A</td><td>Block</td><td>This is a new detection.</td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="ebd3f2df15c74ddcbf6220c9b5ec246a"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...b5ec246a</span></button></rule-id></td><td>N/A</td><td>Generic Rules - Unauthenticated RCE </td><td>N/A</td><td>Block</td><td>This is a new detection.</td></tr><tr><td>Cloudflare Free Ruleset</td><td><rule-id id="db003b39b7774859a8d588ce33697a1a"><button title="Copy rule ID" aria-label="Copy rule ID" class="border-border bg-muted hover:border-foreground/30 hover:bg-accent inline-flex cursor-copy items-center rounded-md border px-1.5 py-0.5 transition-colors duration-150"><span class="font-mono text-[0.8125rem] font-medium">...33697a1a</span></button></rule-id></td><td>N/A</td><td>Generic Rules - SQLi </td><td>N/A</td><td>Block</td><td>This is a new detection.</td></tr></tbody></table>

2026/7/17
阅读更多

推荐订阅

每日新闻.

The Art of Chawye Hsu

Recent content on Yuko's Blog