megachangelog
Security2026-09-25

WAF emergency rules for WordPress and JFrog Artifactory vulnerabilities

Cloudflare's Web Application Firewall has added new managed rules to block critical vulnerabilities in WordPress (path traversal, LFI, XSS) and JFrog Artifactory (authentication bypass). Administrators should apply vendor patches to fully secure their origin servers.

This update provides immediate defense against critical vulnerabilities affecting WordPress and JFrog Artifactory, including path traversal, local file inclusion (LFI), cross-site scripting (XSS), and authentication bypass exploits.

Key Findings

  • CVE-2026-87902: A high-severity Path Traversal and Local File Inclusion (LFI) vulnerability affecting WordPress. Unauthenticated attackers can exploit this flaw to read arbitrary files on the host server, potentially exposing sensitive configuration data or system files.

  • CVE-2026-42018 & CVE-2026-82329: Critical authentication bypass vulnerabilities affecting JFrog Artifactory. Successful exploitation allows unauthenticated attackers to bypass security controls and achieve unauthorized access to the Artifactory instance.

Impact

We strongly recommend that administrators apply the latest vendor patches for WordPress and JFrog Artifactory to fully secure origin servers.

Detailed Rule Changes

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...70a43f96N/AWordpress - Path Traversal, Local File Inclusion - CVE:CVE-2026-87902N/ABlockThis is a new detection.
Cloudflare Managed Ruleset...909a4db4N/AWordpress - XSS - CommentN/ABlockThis is a new detection.
Cloudflare Managed Ruleset...c797ef03N/AJFrog Artifactory - Authentication Bypass - CVE:CVE-2026-42018N/ABlockThis is a new detection.
Cloudflare Managed Ruleset...a813ac74N/AJFrog Artifactory - Authentication Bypass - CVE:CVE-2026-82329N/ABlockThis is a new detection.
wafsecuritywordpressjfrogvulnerability

Source: original entry ↗