megachangelog
Security2026-04-07

WAF Release: New RCE, Auth Bypass, and XSS Detection Rules

This release adds critical WAF detection rules for MCP Server RCE (CVE-2026-23744), SolarWinds authentication bypass (CVE-2025-40552), and XSS injection via HTTP cookie event handlers. These protections prevent arbitrary code execution, unauthorized access, and session hijacking attacks.

This week's release introduces new detections for a critical Remote Code Execution (RCE) vulnerability in MCP Server (CVE-2026-23744), alongside targeted protection for an authentication bypass vulnerability in SolarWinds products (CVE-2025-40552). Additionally, this release includes a new generic detection rule designed to identify and block Cross-Site Scripting (XSS) injection attempts leveraging "OnEvent" handlers within HTTP cookies.

Key Findings

  • MCP Server (CVE-2026-23744): A vulnerability in the Model Context Protocol (MCP) server implementation where malformed input payloads can trigger a memory corruption state, allowing for arbitrary code execution.

  • SolarWinds (CVE-2025-40552): A critical flaw in the authentication module allows unauthenticated attackers to bypass security filters and gain unauthorized access to the management console due to improper identity token validation.

  • XSS OnEvents Cookies: This generic rule identifies malicious event handlers (such as onload or onerror) embedded within HTTP cookie values.

Impact

Successful exploitation of the MCP Server and SolarWinds vulnerabilities could allow unauthenticated attackers to execute arbitrary code or gain administrative control, leading to a full system takeover. Additionally, the new generic XSS detection prevents attackers from leveraging browser event handlers in cookies to hijack user sessions or execute malicious scripts.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...0aa410afN/AGeneric Rules - Command Execution - 5 - BodyLogDisabledThis is a new detection.
Cloudflare Managed Ruleset...9131ec2fN/AGeneric Rules - Command Execution - 5 - HeaderLogDisabledThis is a new detection.
Cloudflare Managed Ruleset...551eb9e5N/AGeneric Rules - Command Execution - 5 - URILogBlockThis is a new detection.
Cloudflare Managed Ruleset...d46229ebN/AMCP Server - Remote Code Execution - CVE:CVE-2026-23744LogBlockThis is a new detection.
Cloudflare Managed Ruleset...a864b9c2N/AXSS - OnEvents - CookiesLogBlockThis is a new detection.
Cloudflare Managed Ruleset...a78ad04eN/ASQLi - Evasion - BodyLogDisabledThis is a new detection.
Cloudflare Managed Ruleset...40732d48N/ASQLi - Evasion - HeadersLogDisabledThis is a new detection.
Cloudflare Managed Ruleset...e68a99b5N/ASQLi - Evasion - URILogDisabledThis is a new detection.
Cloudflare Managed Ruleset...3e8143d2N/ASQLi - LIKE 3 - BodyLogDisabledThis is a new detection.
Cloudflare Managed Ruleset...70e7fb97N/ASQLi - LIKE 3 - URILogDisabledThis is a new detection.
Cloudflare Managed Ruleset...4c538bd9N/ASQLi - UNION - 2 - BodyLogDisabledThis is a new detection.
Cloudflare Managed Ruleset...61c439c9N/ASQLi - UNION - 2 - URILogDisabledThis is a new detection.
Cloudflare Managed Ruleset...cf33ea10N/ASolarWinds - Auth Bypass - CVE:CVE-2025-40552LogBlockThis is a new detection.
wafsecurityrcexsscvedetection

Source: original entry ↗

More from Cloudflare

Follow Cloudflare to get its new changes in your feed and email digest.

Improvement2026.8.2100.0

Cloudflare One Client for macOS 2026.8.2100.0

GA release for macOS Cloudflare One Client with improved split tunnel handling that no longer briefly blocks traffic during reconnects, support for non-RFC 1918 local IPv4 networks, faster connects with lower memory use, and numerous reliability fixes across DNS, reauthentication, and client stability.

macosvpnreliabilityperformancedns
Improvement2026.8.2100.0

Cloudflare One Client for Windows 2026.8.2100.0

This GA release improves split tunnel reliability, adds support for non-RFC 1918 local networks, optimizes connection performance with faster reconnections and lower memory usage, and includes numerous bug fixes for DNS, registration, and network handling. The client now features a service recovery mechanism that automatically restarts on system unlock and better handles large hosts files without blocking traffic.

windowsvpnclienttunneldns
Improvement2026.8.2100.0

Cloudflare One Client for Linux 2026.8.2100.0

New GA release for Linux with improved split tunnel handling that no longer briefly blocks traffic during reconnects, support for non-RFC 1918 local IPv4 networks, faster tunnel reconnections, and lower memory usage. Includes numerous stability and reliability fixes for DNS, reconnection behavior, and crash issues.

linuxvpnclientperformancestability
See all Cloudflare changes →