C

Cloudflare One (Zero Trust) Changelog

C
Cloudflare One (Zero Trust) Changelog Security v2026.7.1210.1

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.7.1210.1)

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Improved connection reliability: the client now swaps protocol order after repeated connectivity-check failures, which helps when HTTP/3 is blocked after the QUIC handshake. Fixed issue where a certificate error could be i…

C
Cloudflare One (Zero Trust) Changelog Security v2026.7.1210.1

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.7.1210.1)

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Improved connection reliability: the client now swaps protocol order after repeated connectivity-check failures, which helps when HTTP/3 is blocked after the QUIC handshake. Fixed issue where a certificate error could be inc…

C

Access - Static OAuth client credentials for MCP server portals

MCP server portals can now connect to upstream MCP servers that require a pre-registered OAuth client. This supports OAuth providers that do not offer Dynamic Client Registration or have disabled it. This unlocks portal connections to major SaaS providers such as Slack and GitHub, whose MCP servers do not yet support DCR. When adding an MCP server, administrators can enter the client ID and client…

C

Cloudflare One, Gateway - Control Cloudflare Gateway DNS caching with a maximum TTL setting

You can now set a maximum time-to-live (TTL) for DNS responses returned by Gateway. When an upstream DNS record has a TTL that exceeds the configured maximum, Gateway caps it to your specified value. This ensures that DNS policy changes - such as blocking a newly identified malicious domain - take effect faster across all clients. The setting is available at two levels: Account level - In Traffic…

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.880.0

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.6.880.0)

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page. This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.880.0

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.880.0)

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page. This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.880.0

Cloudflare One Client - Cloudflare One Client for Linux (version 2026.6.880.0)

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page. This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

C

Access - Browser-based login for plaintext HTTP private applications

Cloudflare Access now uses the standard browser-based login flow for private applications served over plaintext HTTP on port 80. Previously, plaintext HTTP private apps fell back to the same session flow used for SSH, RDP, and other non-HTTP protocols: users got an Authentication required pop-up from the Cloudflare One Client, then had to select the notification to open a browser and log in. Now,…

C

Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Restart, reboot, or shut down a Cloudflare One Appliance from the dashboard

You can now restart, reboot, or shut down a Cloudflare One Appliance directly from the dashboard or via API. Restart — Restart managed services. Purges temporary and (optionally) persistent state. Reboot — Power cycle the appliance. Optionally, purge persistent state. Re-applies configuration starting from scratch. Shutdown — Power off the appliance. Optionally, purge persistent state. The machine…

C

Gateway - New header control options for Gateway HTTP policies

Cloudflare Gateway now supports advanced header control on Allow policies. Administrators can add, overwrite, or delete headers on matching requests using static values or dynamic variables. Header operations Gateway HTTP policies using the Allow action support three operations in rule_settings: Operation API field Behavior Add add_headers Appends a value to the header. Existing values are preserv…

C

Access, Cloudflare One - Bulk print PDFs for browser-based RDP

Users in browser-based RDP sessions can now print multiple PDF files as a single print job. Copy the files to your clipboard on the remote machine, then select Print all PDFs in the clipboard panel. The files are combined into one PDF and sent to your local printer. Bulk print is available in Chromium-based browsers and Firefox. For more information, refer to Print PDFs for browser-based RDP.

C

Gateway, DNS - Internal DNS is now generally available

Internal DNS is now generally available. Internal DNS provides authoritative and recursive DNS for private networks on the same global network and control plane you already use for public DNS, Zero Trust, and application services. Why it matters Consolidate DNS operations. Public and private DNS run on one platform, with one API, one audit trail, and one place to set policy. Simplify split-horizon…

C

Data Loss Prevention - Source code detection improvements

Data Loss Prevention (DLP) source code detection now focuses on identifying whole source code file uploads and downloads. Previously, source code detection performed partial scans resulting in a higher rate of false positives. Since only whole source code files are evaluated, code embedded in other content — such as chat messages, documentation, or code samples — is no longer flagged as source cod…

C

Digital Experience Monitoring - Wi-Fi signal and network performance analytics for Cloudflare One Client devices

Digital Experience Monitoring (DEX) provides visibility into device, network, and application performance across your Cloudflare SASE deployment. The Device Monitoring page now analyzes hardware and network data between a Cloudflare One Client device and Cloudflare's edge, so you can diagnose connectivity and performance issues. Previously, this data was only available in raw DEX Device State Even…

C

Cloudflare Tunnel, Cloudflare Tunnel for SASE, Cloudflare Mesh - Zero Trust Networks route endpoints and Cloudflare Tunnel connections field retiring on October 5, 2026

On October 5, 2026, two changes take effect across the Zero Trust Networks API and Cloudflare Tunnel API: the CIDR-encoded route endpoints are removed, and tunnel list and get responses no longer include the connections field. If you manage private network routes or read tunnel connection details through the API, cloudflared, Terraform, or another integration, review the changes in the following s…

C

Cloudflare One, Cloudflare WAN - IPsec downgrade protection (beta)

Cloudflare IPsec now supports the IKE_SA_INIT_FULL_TRANSCRIPT_AUTH IKEv2 extension to protect against downgrade attacks on IPsec tunnels. IKEv2's original authentication design has each endpoint sign only its own outbound messages, not the full handshake transcript. A quantum-capable on-path attacker can exploit this to bypass post-quantum key exchange by downgrading the connection to classical cr…

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.850.0

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.850.0)

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page. This hotfix addresses a Windows authentication issue in the embedded WebView2 browser. Single sign-on could fail to use the Windows primary account, causing users to be prompted for an interactive sign-in. The embedded authentication browser now allows SSO providers to use the OS primary…

C

Access, Cloudflare One - File transfer controls for browser-based RDP (beta)

You can now configure file transfer controls for browser-based RDP with Cloudflare Access, allowing you to restrict whether users can upload or download files between their local machine and the remote Windows server. This feature is useful for organizations that support bring-your-own-device (BYOD) policies or third-party contractors using unmanaged devices. By restricting file transfers, you can…

C

Browser Isolation, Cloudflare One - Browser Isolation support for authorization proxy endpoints

Browser Isolation now supports Gateway authorization proxy endpoints. You can apply HTTP Isolate policies to traffic routed through authorization proxy endpoints, the same way you can for traffic from the Cloudflare One Client. Previously, only source IP proxy endpoints supported Browser Isolation, and only with non-identity policies. Because authorization proxy endpoints authenticate users throug…

C

Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Self-serve registration of Cloudflare One Virtual Appliance in the dashboard

You can now register a Cloudflare One Virtual Appliance and generate its license key directly from the dashboard, without contacting your account team. On the Connectors page, select Add an appliance and choose Virtual appliance to register a virtual appliance and generate its authentication key. Use Regenerate authentication key from a virtual appliance connector's menu to rotate its key. The pre…

C

Cloudflare Mesh, Cloudflare One - Hostname routing for Cloudflare Mesh

You can now add hostname routes to a Cloudflare Mesh node, in addition to CIDR routes. Client device Requests wiki.internal.local DNS query ↓ Cloudflare Gateway Returns a token IP, then rewrites the destination to the real private IP. 100.80.0.0/16 Hostname route ↓ Mesh node Forwards traffic to the host on the local network ↓ Private host wiki.internal.local · 10.0.0.50 Instead of managing IP rang…

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.836.0

Cloudflare One Client - Cloudflare One Client for Linux (version 2026.6.836.0)

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page. This package is the same release as 2026.6.822.0, with a fix for our RPM package. Previously the repository served a single build to every OS version, so an install could pull a dependency that isn't available on that release. The repository now serves the correct build for each operating s…

C

Access - Independent MFA for infrastructure applications

Access for Infrastructure now supports independent multi-factor authentication (MFA) for SSH connections using YubiKey PIV keys. This adds a hardware-backed second factor to SSH access, ensuring that a compromised device session alone is not sufficient to reach your servers. With per-application and per-policy configuration, you can enforce PIV key authentication for sensitive usernames (for examp…

C

Access - Fix redirect URL fragment encoding for single-page applications

Access now correctly preserves URL fragment characters (/, ?, =, &, ;) when redirecting users back to an application after login. Previously, these characters were encoded with encodeURIComponent, which mangled fragment-based routes used by single-page applications (SPAs). For example, an SPA URL like https://app.example.com/#/dashboard?tab=settings&view=advanced would previously redirect to a bro…

C

Gateway, Cloudflare One, Cloudflare Fundamentals - New permissions and roles for Gateway policies and lists

You can now assign granular, resource-scoped roles for Cloudflare Gateway firewall policies and Zero Trust lists. Administrators can delegate access to specific policy types or list management without granting account-wide or product-wide control. What is new When you add a member or create a permission policy, the following resource-scoped roles are now available: RoleDescriptionZero Trust Gatewa…

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.822.0

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.6.822.0)

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page. This release introduces multiple features from our previous beta release into stable release, including: The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-labe…

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.822.0

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.822.0)

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page. This release introduces multiple features from our previous beta release into stable release, including: The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-la…

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.822.0

Cloudflare One Client - Cloudflare One Client for Linux (version 2026.6.822.0)

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page. This release introduces multiple features from our previous beta release into stable release, including: The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-labe…

C

Cloudflare One, Access - Service token support for MCP server portals

You can now connect autonomous agents and bots to an MCP server portal using an Access service token. Service token sessions can reach upstream MCP servers through the portal without a browser-based OAuth flow. To set this up: Add a Service Auth policy that matches your service token to the portal's Access application. Add a Service Auth policy that matches the same token to each linked MCP server…

C
Cloudflare One (Zero Trust) Changelog Security v2026.6.782.1

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.6.782.1)

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page. This beta release introduces upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the Secure Enclave whenever available to provide stronger protection against device impersonation. Additional changes and improvements This release also i…