C

Cloudflare One (Zero Trust) Changelog

C

Cloudflare One, Access - Access for Infrastructure now supports tagged targets and tag-based target criteria

Access for Infrastructure now integrates with Resource Tagging. You can attach key-value tags to infrastructure targets and use them in access policies. You can manage tags on targets inline when you create or edit a target or through the central Resource Tagging API. Cloudflare keeps tags in sync across both methods. Infrastructure applications also support a target criteria model with include, r…

C

Access - Require fresh authentication for SAML identity providers

Cloudflare Access can now request fresh authentication from a SAML identity provider for every login. Turn on Require reauthentication in the Cloudflare dashboard, or set force_authn to true through the API. Access will then set ForceAuthn to true in signed and unsigned SAML authentication requests. This option is useful when an application requires users to reauthenticate at the identity provider…

C

Data Loss Prevention - Discover where sensitive data goes before you create a Data Loss Prevention policy

Passive Detection for Cloudflare Data Loss Prevention (DLP) lets you learn from your Gateway traffic before deciding what to log or block. Discover the sensitive data types in sampled traffic, explore their destinations, and use the findings to build policies around your organization's needs. The dashboard brings together detections from sampled HTTP request and response bodies. Select an entry to…

C
Cloudflare One (Zero Trust) Changelog Security v2026.8.1290.1

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.8.1290.1)

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM. Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum…

C
Cloudflare One (Zero Trust) Changelog Security v2026.8.1290.1

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.8.1290.1)

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM. Improved DNS reliability on networks with lower MTUs by clamping the TCP maxim…

C

CASB - New CASB integration for Zoom

Cloudflare CASB now integrates with Zoom. The integration connects through Cloudflare's pre-built OAuth application — no manual app setup in Zoom is required. After an initial scan, CASB continuously scans your Zoom account to surface new findings as your environment changes. Zoom is widely used for meetings, webinars, and collaboration. Misconfigurations in account settings, meeting security cont…

C

Browser Isolation, Cloudflare One - Improved iOS tap-to-type experience for Browser Isolation

Browser Isolation has improved the tap-to-type experience for users on iOS devices. Previously, Browser Isolation displayed a full-screen overlay with the message tap to type when users focused a text field. The prompt now appears inline over the focused text field, reducing disruption when users enter text in isolated sessions. If the focused text field is too small to display the full prompt, Br…

C

Cloudflare Tunnel, Cloudflare One, Cloudflare WAN, Cloudflare Mesh - Create multiple Cloudflare Tunnel and Cloudflare Mesh routes at once

You can now create multiple Cloudflare Tunnel and Cloudflare Mesh routes from the Routes page in a single action, instead of submitting one route at a time. When creating a route, you can now: Add multiple destinations at once — Enter a comma-separated list of CIDR ranges or hostnames to create several routes of the same type and connector together. Queue up multiple routes — Select Add another to…

C

Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Configure DHCP options from the dashboard on Cloudflare One Appliance

You can now configure custom DHCP options directly from the dashboard when the Cloudflare One Appliance is acting as the DHCP server for a LAN. In LAN configuration, under DHCP server options, select Add DHCP option to choose from common options for PXE / iPXE boot, VoIP phone provisioning, and vendor-specific configuration, or select Add custom option to enter your own option code, type, and valu…

C

Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Define custom applications for breakout and prioritized traffic from the Cloudflare One Appliance dashboard

You can now define custom applications for breakout and prioritized traffic on the Cloudflare One Appliance directly from the dashboard, without calling the API. In Traffic Steering > Breakout traffic or Prioritized traffic, select Assign application traffic > Add to create a custom application matched by Hostnames, IP subnets, and/or the new Source subnets field, alongside Cloudflare-managed appl…

C
Cloudflare One (Zero Trust) Changelog Security v2026.7.1376.0

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.7.1376.0)

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page. Fixed a rare but critical issue where the client could fail to connect or switch organizations due to an invalid registration after switching installed client versions. Additionally, this hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms…

C

Access - Access service token secrets use a scannable format

Cloudflare Access service token Client Secrets created on or after August 26, 2026, use the format cfast_[40 alphanumeric characters][8-character checksum]. The prefix and checksum make these credentials easier for secret scanning tools to identify with fewer false positives. Existing service token secrets continue to work and do not require rotation. Both formats use the same Client ID and the sa…

C

Access - Temporarily turn off Access service tokens

Cloudflare Access administrators can now temporarily turn off service tokens without deleting them. A disabled token cannot authenticate, but its configuration remains available so administrators can turn it on again later. Turning off a token also stops any previous secret in an active rotation grace period. Use this control to contain suspected credential exposure or pause an automated service.…

C

Access - Grace periods for service token rotation

Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication. The dashboard offers grace periods from one hour to 30 days. Administrators can also revoke the previous secret immediately. The API accepts an RFC 3339 expiration t…

C

Cloudflare One, Access - MCP server portals support MCP 2026-07-28 specification

MCP server portals support the stateless MCP 2026-07-28 specification for client and upstream server connections. The portal's /mcp endpoint automatically accepts stateless MCP 2026-07-28 requests and earlier 2025 Streamable HTTP clients. When the portal connects to an upstream Streamable HTTP server, it checks for MCP 2026-07-28 support and falls back to the 2025 handshake when needed. Client and…

C

Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Download the Cloudflare One Virtual Appliance for your hypervisor from the dashboard

When you register a Cloudflare One Virtual Appliance, you can now select your hypervisor and download the appliance directly from the dashboard — no need to look up asset URLs. On the Connectors page, select Add an appliance, choose Virtual appliance, then select your hypervisor: VMware ESXi, Proxmox, or libvirt/KVM. Download the OVA image (VMware ESXi) or the install script (Proxmox and libvirt/K…

C

Data Loss Prevention - Test Data Loss Prevention profiles without sending traffic through Gateway

Test scan lets you check how Data Loss Prevention (DLP) evaluates sample content before you apply a profile to production traffic. Paste text, upload a file, or upload a HAR file, then select the profiles you want to test. Test scan sends content directly to the DLP scanner. Gateway policies are not evaluated, no traffic passes through Gateway, and no Gateway activity logs are created. Results inc…

C

CASB - Automatically remediate Microsoft 365 and Google Workspace findings with API-based CASB remediation policies

Cloudflare CASB is an API-based (agentless) tool that continuously scans your SaaS and cloud applications for security misconfigurations and data exposure. You can now use CASB remediation policies to automatically fix a finding or send a webhook the moment CASB detects it, without manual triage. Remediate Microsoft 365 and Google Workspace findings A policy can perform a first-party remediation a…

C
Cloudflare One (Zero Trust) Changelog Security v2026.7.1343.0

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.7.1343.0)

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page. This release introduces multiple features from our previous beta release into stable release, including: When reauthentication is needed for any reason, the notifications are clearer and reduce the actions needed to get you back to work by redirecting to the browser for authentication inste…

C
Cloudflare One (Zero Trust) Changelog Security v2026.7.1343.0

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.7.1343.0)

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page. This release introduces multiple features from our previous beta release into stable release, including: When reauthentication is needed for any reason, the notifications are clearer and reduce the actions needed to get you back to work by redirecting to the browser for authentication ins…

C
Cloudflare One (Zero Trust) Changelog Security v2026.7.1343.0

Cloudflare One Client - Cloudflare One Client for Linux (version 2026.7.1343.0)

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page. This release introduces multiple features from our previous beta release into stable release, including: When reauthentication is needed for any reason, the notifications are clearer and reduce the actions needed to get you back to work by redirecting to the browser for authentication inste…

C

Cloudflare Network Firewall, Magic Transit, Cloudflare WAN - Threat Intel Lists supported in Unified Routing

Cloudflare Advanced Network Firewall Threat Intel Lists are now supported for accounts using Unified Routing mode. This feature requires a Cloudflare Advanced Network Firewall subscription. Support for additional features - Rate Limiting and Managed Rulesets - is planned. For the full list of current beta limitations, refer to Traffic steering beta limitations.

C

Access, Cloudflare Fundamentals - Access resource lists now support resource-scoped roles

Members with only resource-scoped Access roles can now open Access resource list pages in the Cloudflare dashboard and call list endpoints in the API. They no longer need an additional account-scoped read-only role to list resources. The dashboard and API return only resources included in the member's permission policy scopes. Filtering applies to Access applications, policies, service tokens, and…

C

Cloudflare Tunnel, Cloudflare Tunnel for SASE - Configure origin application settings for Cloudflare Tunnel in the dashboard

You can now configure origin application settings directly in the Cloudflare dashboard when adding or editing a published application route for a Cloudflare Tunnel. These settings control how cloudflared connects to your origin server and were previously only available in the Cloudflare One dashboard or via local configuration files. When editing a published application, expand Additional applicat…

C

Email security - Post-quantum key exchange for MX deployments

Cloudflare Email Security now supports post-quantum hybrid key exchange with X25519MLKEM768 on the SMTP connections we make to receive and deliver mail. Deploying Email Security in front of a provider that supports post-quantum hybrid key agreement (like Google Workspace) will create a TLS 1.3 connection using post-quantum key agreement. Inbound MX connections and outbound delivery connections now…

C

Workers, Access - You can now enable Access on a Worker or all Workers at once

You now have two new ways to protect your Workers with Cloudflare Access. Protect an application across all its domains at once Until now, if a Worker was reachable on a route, a Custom Domain, and a workers.dev URL, you had to manually add each one to an Access application and keep the list in sync whenever routes or domains changed. Now, Access attaches the policy to the Worker itself, so every…

C

Gateway - Detect and control software package downloads with package registry security

Cloudflare Gateway can now detect software package downloads and give you policy control over supply chain traffic. When a developer or CI/CD pipeline downloads a package through Gateway, the proxy identifies the registry protocol from the request URL and extracts the package ecosystem, name, version, and namespace. You can then write HTTP policies using pkg.* selectors to allow or block package d…

C

Email security - Block emails by content with blocked content rules

Cloudflare Email security now lets administrators write their own content-based blocking rules. A new Blocked content area under Policies & rules lets you define a plaintext string or a regular expression, choose whether to scan the message subject, body, or both, and automatically block any message that matches. Create rules using either plaintext matches or regular expressions — useful for block…