megachangelog
Security2026-08-04

WAF Release - New Rules & Enhanced Cloud Protection

New WAF rules added for Microsoft SharePoint RCE (CVE-2026-50522) and Rails RCE (CVE-2026-66066) vulnerabilities. Enhanced SSRF cloud protection rules with improved detection logic and updated rule actions including new block behaviors.

This release introduces new rules and updates Microsoft SharePoint RCE alongside enhanced SSRF cloud protection rule actions.

Key Findings

  • CVE-2026-50522: An insecure deserialization vulnerability in Microsoft SharePoint Server. This may allow an unauthenticated attacker to execute arbitrary code using crafted requests.
  • CVE-2026-66066: An improper input processing vulnerability in Ruby on Rails Active Storage image variant transformations. This may allow an unauthenticated attacker to perform arbitrary file reads and achieve Remote Code Execution (RCE) using maliciously crafted payload requests.
  • Generic Cloud Protections: Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...052b07cfN/AMicrosoft SharePoint - Remote Code Execution - CVE:CVE-2026-50522LogBlock

This is a new detection.

Cloudflare Managed Ruleset...3a5b40d6N/ARails - Arbitrary File Read & RCE - CVE:CVE-2026-66066BlockBlock

This was labeled as File Upload - RCE.

Cloudflare Managed Ruleset...8242627bN/ASSRF - LocalDisabled -

This detection has been removed.

Cloudflare Managed Ruleset...743a63ecN/ASSRF - Local - 2 - BetaDisabled -

This detection has been removed.

Cloudflare Managed Ruleset...c2e84e2dN/ASSRF - Cloud - BetaDisabled -

This detection has been removed.

Cloudflare Managed Ruleset...ab8af26fN/ASSRF - Cloud - 2 - BetaDisabled -

This detection has been removed.

Cloudflare Managed Ruleset...25ba9d7cN/ASSRF - CloudDisabledBlock

We are changing the action for this rule from Disabled to BLOCK

Cloudflare Managed Ruleset...01a076ebN/ASSRF - Local - BetaDisabled -

This detection has been removed.

wafsecurityrcessrfcloud

Source: original entry ↗