megachangelog
Cloudflare logo

Cloudflare Changelog

Cloudflare — Cloud, Security product updates and releases, tracked on megachangelog.


Announcement

Certificate Transparency Monitoring is now Generally Available

Certificate Transparency Monitoring is now generally available across all Cloudflare plans with automatic filtering of Cloudflare-issued certificates and improved alert emails with clearer details and dashboard links for easier management.

ssl-tlscertificate-managementsecuritymonitoringga
Feature

Control Realtime SFU DataChannel delivery options

Realtime SFU DataChannels now support unordered and partially reliable delivery modes alongside the default reliable and ordered behavior. Applications can configure delivery settings to match payload requirements, choosing between full reliability, unordered delivery, or time/retry-bounded options for use cases like game state, sensor updates, and chat.

webrtcrealtimedatachannelapi
Feature

Block emails by content with blocked content rules

Cloudflare Email Security now lets administrators create custom content-based blocking rules using plaintext strings or regular expressions to stop targeted phishing, known-bad phrases, and organization-specific content patterns. Rules can scan the message subject, body, or both, with built-in regex validation and automatic blocking of matching emails.

email-securitysecurityrulesphishingcontent-filtering
Feature

Independent MFA supports FIDO2 for infrastructure applications

Infrastructure applications now support independent multi-factor authentication using FIDO2 keys for SSH access. Users can enroll FIDO2 keys through the App Launcher and configure them at both application and policy levels.

mfafido2infrastructuresshsecurity
Security2026-08-11

WAF Protection for vBulletin RCE and Detection Improvements

Cloudflare WAF now protects against vBulletin CVE-2026-61511 remote code execution vulnerability with a new detection rule. Two existing detections for version control information disclosure and vBulletin code injection have been improved and merged into their base rules for stronger coverage.

wafsecuritycvevulnerabilityvbulletin
Announcement

Hostname routing is now generally available with new public IP range

Hostname routing is now GA, allowing you to route traffic by hostname across Cloudflare One connectors instead of managing static IP lists. The default IP range for initial resolved IPs is changing from a CGNAT range to Cloudflare's public range (172.64.128.0/20 for IPv4) to address Chrome 142's Local Network Access restrictions that were blocking background requests.

hostname-routingtunnelsasegatewaynetworking
Improvement

Pages now skips superseded queued builds

Pages automatically skips a queued build when a newer build for the same project, branch, and deployment target is also queued, improving build queue efficiency.

pagesbuildsoptimizationdeployment
Improvement

Cloudflare Status page rebuilt with new notification system

The Cloudflare Status page has been rebuilt while maintaining all existing APIs and bookmarks. It now includes independent notifications via email, webhook, Slack, Discord, and Google Chat that work even during Cloudflare outages, Markdown support for AI agents, and separate RSS/Atom feeds for incidents and maintenance.

status-pagenotificationsapireliabilityintegration
Feature

Stream live logs from Cloudflare Tunnel in the dashboard

Real-time tunnel log streaming is now available in the Cloudflare dashboard, allowing you to stream logs from single or multiple connectors with filtering by log level, event type, and HTTP method. This brings live debugging previously only available in Cloudflare One dashboard to the main dashboard interface.

tunnelloggingdashboardnetworkingmonitoring
Announcement

Turnstile Spin is now generally available

Turnstile Spin is now generally available with three setup paths for creating and deploying Turnstile widgets. Users can set up via the dashboard, Wrangler CLI, or AI coding agents, with automated server-side siteverify integration and validation checks.

turnstilebot-managementsecuritysetupai-assisted
Feature

Workers AI and AI Gateway unify model access and billing

Workers AI and AI Gateway now provide a unified interface for accessing both first-party and third-party AI models with shared bindings, REST APIs, and consolidated billing through prepaid credits. This enables centralized observability, logging, caching, and rate limiting across all model providers.

workers-aiai-gatewayapibillingobservability
Announcement1.0 preview

Sandbox SDK 1.0 preview available on @next

Sandbox SDK 1.0 is now available for preview under the npm @next tag, featuring a simplified API with unified execution interface, RPC-only transport, improved terminal support, and modular code interpreter. The stable 0.12.x release continues to be supported for existing applications.

sdkcontainersapipreviewrpc
Feature

Radar Researcher beta and WebMCP support now available

Cloudflare Radar now includes Radar Researcher, an AI-powered assistant for exploring Internet trends and traffic data through voice or text queries with interactive charts. Additionally, Radar now supports WebMCP, enabling browser-based AI agents to navigate Radar data and use tools like URL scanning and domain lookup.

radaraiapianalyticsbeta
Security2026-08-07

WAF Updates: WordPress XSS (CVE-2026-64638) and Command Injection Rule Disabling

Updated WordPress XSS rule metadata in the Managed and Free Rulesets to identify CVE-2026-64638, a pre-authentication reflected cross-site scripting vulnerability on WordPress login screens. Also disabled the Command Injection - Obfuscation rule as its detection logic has been deprecated.

wafsecuritywordpressxsscve-2026-64638
Announcement

MySQL support in Hyperdrive is now generally available

Hyperdrive now provides general availability support for MySQL databases, allowing you to connect to any MySQL database from Cloudflare Workers with optimized connection pooling, caching, and no code changes required for existing drivers and ORMs.

hyperdrivemysqlworkersdatabaseavailability
Feature

Cloudflare Mesh Docker container image

Cloudflare Mesh now runs as a Docker container image on Docker Hub, supporting Docker Compose, Kubernetes, and OCI-compatible runtimes with amd64 and arm64 architecture support. Built-in source NAT eliminates the need for VPC route table changes, and deployments can span Docker Compose, Kubernetes StatefulSets, sidecars, and CI/CD pipelines with automatic failover support.

cloudflare-meshdockerkubernetesnetworkingcontainers
Feature

Radar expands with AS-level connectivity and upstream provider widgets

Cloudflare Radar now includes two new widgets on AS pages showing how networks reach the Internet through Tier-1 providers: an AS-level connectivity graph displaying BGP paths and an Upstream providers chart tracking path shares over time. Both are backed by new BGP API endpoints for programmatic access to this routing data.

radarbgproutingapianalytics
Feature

Browser Run - Introducing Kitesurf, an agent-first browser

Cloudflare launches Kitesurf, a new stateless browser for Browser Run optimized for AI agents that uses 3–7× less CPU and memory than Chromium. It is available free in beta and can be enabled by adding the browser=kitesurf parameter to Browser Run endpoints.

browser-runai-agentsperformancebetaworkers
Feature

AI Search adds custom domains, authentication, and advanced crawling

AI Search now supports serving search endpoints from your own domain, restricting access with Cloudflare Access authentication, querying multiple instances from a single namespace URL, and discovering website content through link crawling without requiring a complete sitemap.

ai-searchapiauthenticationweb-crawler
Feature

AI Gateway - Track AI spend and catch anomalous usage with User Insights

AI Gateway now includes User Insights, a dashboard providing visibility into AI spending costs, requests, tokens, and adoption while also detecting anomalous user behavior that may indicate compromised credentials or misbehaving agents. The feature requires no additional setup and is available to all AI Gateway customers at no cost.

ai-gatewaysecuritymonitoringcost-trackinganomaly-detection
Feature

Identity-aware controls now available in AI Gateway

AI Gateway now integrates with Cloudflare Access to provide identity-aware controls, allowing you to protect gateway endpoints with Access policies and use authenticated user identity for logs, analytics, routing, and spend controls. Users can set per-user spend limits, control gateway access by user, and filter logs by identity.

ai-gatewayaccessidentitysecurityapi
Improvement

Improved publisher verification details on OAuth consent screens

OAuth consent screens now display shield icons with explanatory text that indicate who owns the application and whether its domain ownership is verified, helping users identify trusted applications more easily.

oauthsecurityauthenticationux
Feature

CI Workflows for Artifacts - Build and deploy on every push

You can now run CI/CD pipelines on Artifacts repos with automatic triggering on push events using the CI SDK. This enables automated building, testing, linting, and deployment to Workers with dependency caching based on lockfile changes.

artifactsworkflowsci-cddeploymentautomation
Feature2026-08-04

Node.js compatibility now enabled by default

Workers now enable Node.js compatibility flags by default for compatibility dates of 2026-08-04 or later, making all Node.js built-in APIs available without additional configuration. Existing projects using earlier compatibility dates are unaffected and can opt in manually.

workersnodejscompatibilityruntime
Security2026-08-04

WAF Release - New Rules & Enhanced Cloud Protection

New WAF rules added for Microsoft SharePoint RCE (CVE-2026-50522) and Rails RCE (CVE-2026-66066) vulnerabilities. Enhanced SSRF cloud protection rules with improved detection logic and updated rule actions including new block behaviors.

wafsecurityrcessrfcloud
Feature

Create Free accounts from the dashboard

Cloudflare users can now create standalone Free accounts directly from the dashboard using a new Create Account button, with support for up to 5 Free accounts per user after 7 days of tenure.

accountsdashboardfeaturefree-tier
Feature

Agent traces for Think, Flue, and AI SDK in Agents SDK

Agent tracing is now available for applications built with the Agents SDK, showing each agent turn with model calls, tool runs, approvals, token usage, and Workers runtime operations. Developers can enable tracing via Wrangler configuration and wrap the AI SDK to automatically capture and inspect traces in the Cloudflare dashboard.

agentsworkersobservabilitytracingai
Feature

AI agents can debug Workers with local tracing

Cloudflare Workers now automatically capture structured OpenTelemetry traces and console logs during local development. AI agents can use the Local Explorer API to identify failing operations, fix code, and verify results without deployment, while developers can inspect traces and logs in a browser UI.

workersdebuggingaiobservabilitytracing
Improvement

Vectorize indexes now support up to 20 million vectors

Vectorize index capacity has doubled from 10 million to 20 million vectors, enabling larger-scale semantic search, recommendation systems, and RAG applications without requiring data to be split across multiple indexes.

vectorizeaivectorscapacitysemantic-search
Feature

Workers - Python and JavaScript Workers can now call each other via RPC

Workers RPC now enables cross-language method calls between Python and JavaScript Workers using Service bindings, with automatic type conversion and exception propagation. No additional dependencies, schemas, or serialization code is required.

workersrpcpythonjavascriptapi
Announcement

Preview: @cloudflare/computer agent runtime

Cloudflare released an early preview of @cloudflare/computer, an open-source agent runtime that provides agents with dynamic compute orchestration between efficient isolates and full Linux containers, plus a virtual filesystem backed by SQLite for file operations and shell command execution.

agentsworkersruntimeopen-sourcepreview
Announcement

R2 SQL billing now enabled for non-enterprise accounts

Billing for R2 SQL is now active on non-enterprise accounts, charging $0.0025 per GB of compressed data scanned, with 10 GB included monthly. All R2 SQL usage beyond the free tier will appear on invoices starting immediately.

r2-sqlbillingpricinganalytics
Announcement

Pipelines billing now enabled for non-enterprise accounts

Billing for Cloudflare Pipelines is now active on non-enterprise accounts. Usage beyond the free tier is billed based on SQL transforms ($0.04/GB) and sinks ($0.03–$0.06/GB depending on output format), with 50 GB/month included for paid Workers plans.

pipelinesbillingpricingworkers
Announcement

R2 Data Catalog billing now enabled

Billing is now active for R2 Data Catalog on non-enterprise accounts, with charges based on catalog operations, compaction data processed, and compaction objects. Each dimension includes a free tier, and usage beyond the included amounts will appear on your next invoice.

r2billingdata-catalogpricing
Feature

Control authorization cookies for multi-domain Access applications

Cloudflare Access now lets administrators control whether authorization cookies are set eagerly across all hostnames or issued only when users visit each one. This new setting is on by default for new applications and helps prevent sign-in loops in browsers with many hostnames.

accessauthorizationcookiesmulti-domainsecurity
Improvement2026.7.1210.1

Cloudflare One Client for Windows (Beta 2026.7.1210.1)

This beta release improves connection reliability through protocol swapping, fixes certificate display errors, DNS parsing issues, MASQUE tunnel stalling, and organization switching problems. Multiple UI crashes, IPv6 multicast routing, Windows 10 compatibility, and credential cleanup issues have also been resolved.

windowsclientbetaconnectivitystability
Improvement2026.7.1210.1

Cloudflare One Client for macOS (Beta)

Beta release with improved connection reliability, DNS handling, and multiple bug fixes for the macOS Cloudflare One Client. Includes MASQUE tunnel stability improvements, certificate error fixes, and better support for configurations with many DNS fallback resolvers.

macosvpnreliabilitydnsbeta
Feature

Access - Static OAuth client credentials for MCP server portals

MCP server portals can now connect to upstream servers requiring pre-registered OAuth clients, supporting providers without Dynamic Client Registration like Slack and GitHub. Administrators can configure client credentials with encrypted storage and custom OAuth endpoints.

accessoauthmcpauthenticationsecurity
Feature

Browser Run adds a Playground to the Cloudflare dashboard

Browser Run now includes a Playground in the Cloudflare dashboard where you can test Quick Actions against a live browser without creating a Worker or deploying code. The Playground lets you test URLs, tune viewport settings, preview outputs, and generate working code in cURL, TypeScript SDK, Python, or Workers Binding format.

browser-rundashboardplaygroundtesting
Feature

Stream - Rotate broadcast keys for live inputs

You can now rotate broadcast credentials for Stream live inputs without changing the input identifier. This allows you to revoke old credentials, disconnect stale broadcasts, and refresh keys as part of your security process while maintaining the same live input.

streamsecuritylive-inputcredentialsapi
Feature4.116.0

Inspect Worker startup performance with Wrangler

Wrangler check startup now reports bundle sizes, CPU activity during startup, and generates a cpuprofile for detailed flamegraph analysis. This helps developers identify code and dependencies that cause cold-start latency before deploying to production.

workersdurable-objectswranglerperformanceprofiling
Feature

Access - Four Code Mode policies for MCP portal admins

Admins can now configure Code Mode policies for MCP server portals with four options: Off, Opt-in, On by default, and Enforced. The legacy allow_code_mode boolean field is deprecated in favor of a new code_mode field in the Cloudflare API that supports off, opt_in, default_on, and enforced values.

accessmcpapiadmin
Feature

AI Search integration with Agents SDK, AI SDK, and LangChain

AI Search can now be used directly from popular agent frameworks including Vercel AI SDK, LangChain, and Cloudflare Agents SDK, enabling grounded retrieval in existing applications without manual REST API calls. New packages and integrations provide easy access to AI Search functionality across different development environments.

ai-searchagentssdklangchainvercel-ai
Announcement

Workers - Node.js 24 is now the default for Workers Builds

Workers Builds now uses Node.js 24.18.0 as the default runtime, with Node.js 22.23.2 also preinstalled. You can override the default version using environment variables or configuration files.

workersnodejsruntimebuilds
Security2026-07-29

WAF ruleset update with Nuxt RCE and Fastjson protections

New WAF rules protect against critical vulnerabilities in Nuxt Server Islands and Alibaba Fastjson deserialization, plus enhanced detection for cloud SSRF and obfuscated command injection attacks.

wafsecurityrcessrfvulnerability
Feature

Browser Run adds structured handoff for Human in the Loop

Browser Run now supports structured handoff for Human in the Loop workflows, allowing agents to formally pause and request human intervention via Live View, then resume automatically once the task is complete. This replaces manual intervention management with a reliable pause-and-resume flow using Cloudflare-specific CDP commands.

browser-runautomationhuman-in-the-loopapiworkflows
Breaking

Workers AI models now require paid plan for certain resource-intensive models

Three resource-intensive AI models (Kimi K2.6, Kimi K2.7-code, and GLM 5.2) now require the Workers Paid plan instead of being available on the free tier. This change improves reliability and reduces capacity errors for all users, while many other models remain available on the free plan.

workers-aibillingmodelspricingbreaking
Feature

Gateway now supports maximum DNS TTL settings

Cloudflare Gateway now lets you set a maximum TTL for DNS responses, allowing policy changes like blocking malicious domains to take effect faster. You can configure this at the account level or per DNS location, and two new fields track original and applied TTLs in DNS logs.

dnsgatewaysecuritycachingpolicy
Improvement2026-07-28

Cloudflare MCP servers support new MCP 2026-07-28 Specification

Cloudflare's MCP servers now support the new MCP 2026-07-28 Specification with stateless request handling and compatibility with 2025 Streamable HTTP clients. The /mcp endpoint accepts stateless requests while legacy /sse URLs continue working as aliases, though the deprecated HTTP+SSE transport is no longer served.

mcpworkersagentsapihttp
Feature

Workers tracing — new startActiveSpan() and span.end() runtime APIs

Cloudflare Workers now provides startActiveSpan() and span.end() APIs for writing custom spans that remain open after the callback returns, enabling instrumentation of asynchronous operations like stream pipelines that span multiple callbacks.

workerstracingobservabilityapiruntime
Breaking1.1.1.1

Improved DoH JSON formatting for additional record types

The 1.1.1.1 DoH JSON API now uses human-readable presentation format for additional DNS record types (CAA, NAPTR, RP, IPSECKEY, SVCB, HTTPS, TLSA, SSHFP, OPENPGPKEY) instead of generic hex encoding, and DNSSEC-related records now use numeric algorithm identifiers instead of mnemonic names. This is a breaking change affecting DNS record formatting in JSON responses.

dnsapiformattingdohbreaking
Feature

createTestHarness() API for integration testing Workers

Wrangler now provides createTestHarness(), an API for running integration tests against Workers from any Node.js test runner. The test harness starts a local Worker server with helpers for dispatching requests, resetting storage, and inspecting runtime logs, supporting multi-Worker routing, request mocking with libraries like MSW, and browser testing with Playwright.

workerstestingwranglerapinodejs
Feature

Audit Logs v2 — Resource History

Audit Logs v2 now includes Resource History, allowing you to see the sequence of previous changes to any resource and view side-by-side diffs of what was modified. This feature requires no additional configuration and leverages your existing audit log entries.

audit-logsapicompliancevisibility
Feature0.20.0

Agents SDK adds MCP Specification 2026-07-28 support

Agents SDK v0.20.0 adds client and server support for MCP 2026-07-28, enabling Workers to serve tools and resources without MCP transport sessions. The SDK now supports both new stateless protocol and legacy servers, with improved OAuth validation and isolated server handling for each request.

agentssdkmcpworkersapi
Improvement

Workers Builds now skips superseded queued builds

Workers Builds now automatically skips a queued build when a newer build for the same trigger is also queued, improving build efficiency and reducing unnecessary processing.

workersbuildsci-cdoptimization
Improvement

Agents SDK packages support AI SDK v6 and v7

The agents, @cloudflare/ai-chat, @cloudflare/codemode, and @cloudflare/think packages now support both AI SDK v6 and v7, allowing existing applications to remain on v6 or upgrade to v7 without changing their Cloudflare Agents APIs. Think normalizes streaming, tool completion events, and telemetry across both versions.

ai-sdkagentscompatibilitynodejspackages
Announcement1.0-preview

Sandbox SDK 1.0 preview available on @next tag

Sandbox SDK 1.0 is now available for preview on npm's @next tag with a redesigned, thinner API built on improved Cloudflare Containers. The new version simplifies execution with a single sandbox.exec() interface, removes session state management, uses RPC as the exclusive transport, and makes code interpreters optional extensions.

sandboxcontainerssdkpreviewapi
Fix2026.6.880.0

Cloudflare One Client for macOS - DNS fallback regression fix

This hotfix resolves a regression that caused excessive DNS-over-TCP queries by reverting to UDP-first DNS fallback behavior, which now only uses TCP when responses are truncated instead of querying both protocols in parallel.

dnsmacosfixnetworkingstability
Fix2026.6.880.0

Cloudflare One Client for Windows - DNS Query Fix

Fixed a regression that caused excessive DNS-over-TCP queries by reverting to UDP-first behavior with TCP fallback only when responses are truncated. This reduces unnecessary load on DNS infrastructure.

windowsdnsclientstabilitynetworking
Fix2026.6.880.0

Cloudflare One Client for Linux GA Release

Cloudflare One Client for Linux version 2026.6.880.0 is now available. This release fixes a regression that caused excessive DNS-over-TCP queries by reverting to UDP-first behavior, falling back to TCP only when responses are truncated.

linuxdnsclientstabilityfix
Feature

Sandbox SDK - Run Devin on Cloudflare using Devin Outposts

Devin Outposts enables running Devin agents on Cloudflare infrastructure with isolated sandbox environments powered by Cloudflare Containers, allowing agents to execute code and use development tools securely.

sdkdevinsandboxcontainersai
Announcement

Account Roles API deprecated in favor of Permission Groups API

The Account Roles API is being deprecated and replaced by the Permission Groups API. Users need to migrate to the new API, which has a different response schema with meta objects and scopes instead of the legacy resource-keyed permissions structure.

apideprecationaccount-rolespermission-groupsmigration
Feature

Automatic TLS 1.3 key exchange to origins

Cloudflare now automatically predicts and sends the preferred TLS 1.3 key agreement algorithm in the first ClientHello, eliminating unnecessary HelloRetryRequest round trips and improving handshake performance. The feature defaults to on for all zones and supports post-quantum X25519MLKEM768 hybrid key agreements when origins support them.

ssl-tlssecurityperformancepost-quantumcryptography
Security2026-07-21

WAF Release - New vulnerability rules for Next.js, WordPress, and Adobe ColdFusion

This WAF release introduces new detection rules for vulnerabilities in Next.js, WordPress, and Adobe ColdFusion, with enhanced generic protections against SSRF, LFI, and XSS attacks. Updated rules provide coverage for critical vulnerabilities across multiple frameworks.

wafsecuritynext.jswordpresscves
Feature

View total SQLite storage for Durable Object namespaces

A new Total storage chart in the Cloudflare dashboard lets you monitor SQLite storage usage by Durable Object namespace over time, showing maximum hourly storage to help identify growth patterns and validate data cleanup.

durable-objectssqlitestoragemonitoringdashboard
Improvement

Access - Browser-based login for plaintext HTTP private applications

Cloudflare Access now uses standard browser-based login flow for private applications served over plaintext HTTP on port 80, eliminating the pop-up notification requirement and delivering a consistent experience with HTTPS applications. No configuration changes are needed.

accessauthenticationhttpprivate-appszero-trust
Announcement

Budget alerts now on by default for Pay-as-you-go accounts

Budget alerts are being automatically enabled for eligible Pay-as-you-go accounts with a default $10 threshold, helping users monitor usage-based spending. Users can customize or disable these alerts anytime from their billing settings.

billingalertsworkersnotifications
Feature

Distributor, MSSP, and Agency partners can manage Organization members directly

Distributor, MSSP, and Agency partners can now add and manage Organization members directly from the Cloudflare dashboard without manual Cloudflare assistance. Members automatically gain implicit access to Organization accounts, with consistent labeling and grouping across the dashboard, and Agency partners also get access to the Organizations dashboard.

organizationsmembersdashboardaccess-controlpartners
Feature

Gateway HTTP policies now support advanced header control

Cloudflare Gateway now allows administrators to add, overwrite, or delete HTTP headers on Allow policies using static values or dynamic variables like user identity and device context. This enables fine-grained control over request headers based on identity, device, and network attributes.

gatewayhttp-policiesheadersapisecurity
Security2026-07-17

WAF emergency rules for RCE and SQLi vulnerability exploitation

This emergency release adds four new managed WAF rules to block active exploitation of critical remote code execution and SQL injection vulnerabilities in popular web frameworks. The rules protect against unauthenticated RCE attacks via malicious path sequences and SQLi attacks via unsanitized request parameters.

wafsecurityrcesqliemergency
Feature

Email Service - Preview sent emails in Activity log

You can now preview the full content of sent emails directly from the Email Service Activity log, including rendered HTML, text body, headers, attachments, and raw RFC 5322 source. This makes debugging rendering and content issues easier, as previously only delivery and authentication metadata were available.

emaildebuggingactivity-logpreview
Feature

Bot management fields and ASN support in Cache Rules

Cache Rules now supports bot management fields (score, JA3/JA4 fingerprints, verified bot status, attack/API scores) and the ip.src.asnum field, allowing you to build cache policies that differentiate between automated and human traffic or segment caching by autonomous system number without affecting legitimate user requests.

cache-rulesbot-managementasnsecurityfiltering
Feature

Manage Flagship apps and feature flags from the command line with Wrangler

Wrangler now includes wrangler flagship, a command suite for managing Flagship apps, feature flags, and rollouts from your terminal. Create and configure flags with variations, enable rollouts and splits by percentage or targeting rules, and manage feature flag state through CI/CD pipelines without redeploying your Worker.

wranglerflagshipfeature-flagsclideployment
Feature

Bulk print PDFs for browser-based RDP

Users can now print multiple PDF files as a single print job during browser-based RDP sessions by copying files to the clipboard and selecting Print all PDFs, with support for Chromium-based browsers and Firefox.

rdpprintingaccesscloudflare-one
Announcement

Deprecate legacy Workers KV namespace API routes

Legacy Workers KV API routes under /accounts/{account_id}/workers/namespaces/ are deprecated as of July 15, 2026 and will be removed on October 15, 2026. Users must migrate to the new routes under /accounts/{account_id}/storage/kv/namespaces/, which are direct URL path substitutions with identical request parameters and response payloads.

workerskvapideprecationmigration
Feature

Subscribe to Email Sending events with Queues

Email Sending events can now be published to Queues through event subscriptions, allowing you to track transactional email lifecycle events (delivered, deferred, bounced, failed, rejected, complained) and drive deliverability, suppression, and retry logic based on SMTP responses.

emailqueueseventsdeliverabilityapi
Announcement

Internal DNS is now generally available

Internal DNS provides authoritative and recursive DNS for private networks, consolidating public and private DNS operations on a single platform with unified API, audit trail, and policy management. This simplifies split-horizon DNS and extends Zero Trust controls to DNS resolution.

dnsgatewayzero-trustannouncement
Feature

Workers: Create Temporary Accounts via API

Platforms can now create temporary preview accounts through the Cloudflare REST API, allowing users to deploy and test Workers before signing in. The API returns a claim URL to make the temporary account and resources permanent.

workersapitemporary-accountsdeploymentplatforms
Improvement

Improved reliability for account-wide Web Analytics dashboards

Cloudflare Web Analytics now includes performance optimizations to fix loading failures and timeouts in account-wide dashboards for accounts with over 100 sites. Accounts with up to 1,000 sites can now load aggregate views reliably, with clearer error messaging for larger accounts.

analyticsperformancereliabilitydashboardmonitoring
Security2026-07-14

WAF Release - New rules for critical infrastructure vulnerabilities

Cloudflare WAF adds new detection rules for critical vulnerabilities in Citrix NetScaler ADC/Gateway (CVE-2026-8451) and Progress Kemp LoadMaster (CVE-2026-8037). These rules block exploitation attempts against unauthenticated memory disclosure and remote code execution flaws.

wafsecuritycvecritical-infrastructurevulnerability-detection
Improvement

R2 Data Catalog now optimizes manifest files during compaction

R2 Data Catalog automatically optimizes manifest files as part of compaction, consolidating fragmented manifests and reducing metadata I/O overhead during query planning. This improvement applies automatically to tables with compaction enabled.

r2icebergperformancecatalogmetadata
Feature

R2 Data Catalog now supports read-only API tokens

R2 Data Catalog now accepts read-only API tokens for query engines and read-only clients, eliminating the need for read-write tokens for read-only operations. This allows better adherence to the principle of least privilege by scoping token permissions to only what is needed.

r2apisecuritytokensaccess-control
Improvement

Origin Content Signals for Markdown for Agents

Markdown for Agents now preserves security and cache-relevant response headers from your origin, respects your origin's Content Signals policy, and fixes relative link resolution for directory-style base URLs to prevent incorrect 404 errors.

markdownagentsheaderssecuritycaching
Feature

Precursor - Session-based bot detection

Cloudflare is rolling out Precursor, a client-side JavaScript solution that enables session-based bot detection with continuous behavioral evaluation and real-time challenge re-validation. It integrates with existing protections like Security Rules and can be configured directly from the dashboard to balance security and user experience.

bot-detectionsecuritychallengesclient-sidesession
Feature

Agents can respond to MCP elicitation requests

Cloudflare Agents connected to Model Context Protocol servers can now handle elicitation requests, allowing MCP servers to request user input through form mode for structured data collection or URL mode for out-of-band flows like authorization and payments. Developers can register handlers in onStart() to forward these requests to their UI for user interaction.

agentsmcpworkersapi
Feature

Workers AI - Plain text output for Markdown Conversion

Markdown Conversion service now supports a new plain text output format option. Set output.format to "text" to receive content with Markdown syntax removed, while the default "markdown" format remains unchanged for backward compatibility.

workers-aimarkdownapiconversion
Improvement

Data Loss Prevention - Source code detection improvements

Data Loss Prevention source code detection now focuses on whole file uploads and downloads with a minimum 500-character threshold, reducing false positives from embedded code snippets in chat, documentation, or other content. Users can tune sensitivity via confidence level settings to balance detection accuracy with noise reduction.

dlpsecuritysource-codedetectionfalse-positives
Feature

Workflows supports dynamic delay functions for retries

Workflows now supports dynamic delay functions in step retries, allowing you to calculate adaptive delays based on the failure type and error details. This lets you implement intelligent retry strategies like longer delays for rate-limit errors and shorter delays for transient failures, without additional queue or scheduling logic.

workflowsretryapifeaturereliability
Feature

Workers - Send npm package dependency metadata with uploads

Wrangler now collects and sends npm package dependency information (name, version range, installed version) from your project's package.json during deployments, enabling dependency analytics and future supply chain security features like vulnerability alerting. You can opt out by setting dependencies_instrumentation.enabled to false in your configuration.

workersnpmdependenciessecuritywrangler
Breaking

Zero Trust Networks API: CIDR route endpoints and tunnel connections field retiring

Cloudflare will remove CIDR-encoded route endpoints from the Zero Trust Networks API and retire the connections field from tunnel list and get responses on October 5, 2026. Users managing private network routes or tunnel connection details must migrate to route_id-based endpoints and the dedicated connections endpoint.

apibreakingzero-trustmigrationdeprecation
Breaking

New Durable Object namespaces must use SQLite storage backend

New Durable Object namespaces can no longer be created with the key-value backend and must use SQLite instead. Accounts without existing KV-backed namespaces are affected immediately, while SQLite-backed objects offer feature parity with KV storage plus SQL queries and point-in-time recovery.

durable-objectsbreakingstoragemigrationsqlite
Improvement

DNS Firewall UX refresh with expanded dashboard settings

The DNS Firewall dashboard has been modernized with previously API-only settings now available in the UI, including attack mitigation, rate limiting, negative TTL, and resolver subnet configuration. The cluster table now features resizable and customizable columns, and cluster creation and editing use an improved form layout for faster configuration.

dnsfirewalldashboarduisettings
Feature

Digital Experience Monitoring - Wi-Fi signal and network performance analytics

Digital Experience Monitoring (DEX) now provides device, network, and application performance visibility across Cloudflare SASE deployments. The Device Monitoring page analyzes hardware and network data between Cloudflare One Client devices and Cloudflare's edge, enabling diagnosis of connectivity and performance issues without requiring custom analytics on raw event logs.

dexnetwork-monitoringcloudflare-oneperformanceanalytics
Feature

Cloudflare Drop: Deploy static sites without an account

Cloudflare Drop enables you to deploy static websites instantly by uploading a folder or zip file, receiving a temporary live preview for 1 hour, and optionally claiming the deployment to make it permanent with full management features like custom domains and access controls.

workersdeploymentstatic-sitesaccessibility
Feature

Moondream 3.1 now available on Workers AI

Cloudflare has partnered with Moondream to bring their latest 9B parameter vision language model to Workers AI. The model delivers fast, cost-efficient visual reasoning with support for queries, captions, object detection, and point localization, with first token latency of 20–30 ms for real-time edge inference.

workers-aivisionmodelsinferenceedge-computing
Feature

R2 SQL - Query R2 Data Catalog tables from the dashboard

You can now query R2 Data Catalog tables with R2 SQL directly from the Cloudflare dashboard without needing a CLI or client setup. The built-in SQL editor lets you write, explore, and validate queries interactively with syntax highlighting, autocomplete, and performance statistics.

r2sqldata-catalogdashboardiceberg

Sign up to see more

97 more changes from Cloudflare. Sign up to read the whole changelog.

Sign up free

GitHub or email — no card needed.