Cloudflare introduced new Radar API endpoints to list origins by region, retrieve origin details, and analyze time-series metrics (e.g., connection failures, requests) for major cloud providers like A…
Cloudflare R2 now supports configurable object lifecycle rules to automate retention periods and storage class transitions. Users can set rules to delete objects after a set duration or transition the…
Cloudflare Hyperdrive now supports connecting to private databases using Workers VPC, eliminating the need for Cloudflare Access or service tokens. Users create a TCP VPC Service pointing to their dat…
Cloudflare advanced its post-quantum security timeline to 2029 and launched generally available post-quantum encryption in its IPsec WAN service using hybrid ML-KEM (FIPS 203). The implementation inte…
Cloudflare and Stripe introduced a new protocol allowing coding agents to autonomously provision Cloudflare accounts, domains, and deploy apps without human intervention. The integration leverages Str…
Cloudflare enhanced its Digital Experience Monitoring (DEX) synthetic tests in Cloudflare One, allowing users to export application test logs via Logpush to R2, SIEM tools, or third-party storage beyo…
Cloudflare added new predefined Data Loss Prevention (DLP) profiles to Cloudflare One, including AI prompt protection, expanded financial data detection, and enhanced PII and identifier validations. T…
Cloudflare introduced Secrets Store, a centralized service for encrypting and storing account-level secrets securely across its global data centers. Currently in open beta, it integrates with Cloudfla…
Cloudflare updated its Data Loss Prevention (DLP) feature to scan AI prompts and responses via AI Gateway, complement SaaS application scanning with CASB, and extend support to Zero Trust Free and Pay…
Cloudflare launched Queues, a messaging service integrated with Workers that guarantees delivery, supports batching, retries, dead-letter queues, and pull consumers. Available on Free and Paid plans w…
Cloudflare introduced a GraphQL Analytics API enabling users to query HTTP request data, product-specific metrics (e.g., Firewall, Load Balancing), and packet-level data for Network Analytics users. T…
Cloudflare introduced Version Management, an Enterprise-only feature enabling safe testing, deployment, and rollback of zone configuration changes. Users can create independent versions, deploy to sta…
Cloudflare released Python SDK v5.0.0, dropping Python 3.8 support in favor of 3.9+, adding 11 new API services (e.g., AI Search, Fraud, R2 Data Catalog), and introducing optional aiohttp backend for …
Cloudflare Radar now supports dark mode with a theme selector offering light, dark, and system settings. The theme applies across all Radar pages and embedded graphs, including shared links.
Cloudflare deployed an emergency WAF rule to block a critical cPanel & WHM authentication bypass (CVE-2026-41940) enabling unauthenticated administrative access. The flaw risks full server compromise …
Cloudflare introduced new predefined detection entries for its Data Loss Prevention (DLP) tool, expanding coverage for credential types, webhooks, addresses, tax identifiers, national IDs, financial d…
Cloudflare introduced Data Classification in its DLP product, enabling administrators to label and organize sensitive content using custom labels, templates, and reusable data classes. Classifications…
Cloudflare’s Cloud Observatory now offers enhanced connection metric insights with provider-level, region-level, and percentile breakdowns for TCP/TLS handshake and response durations. Users can compa…
Cloudflare’s R2 dashboard now lets users empty entire buckets or delete folders directly, eliminating the need for scripting or lifecycle rules. The feature streamlines bucket management by combining …
Cloudflare Web Analytics now includes Navigation Type reporting and filtering to track how users navigate pages and whether browser caching (including bfcache) is effective. This helps identify perfor…
Cloudflare launched Go SDK v7.0.0, a major release introducing breaking changes to AI Search, Email Security, and Workers packages. The update removes deprecated metadata types, restructures path para…
Cloudflare released TypeScript SDK v6.0.0, a major update introducing 11 new API resources, 179 return type changes, and 17 removed endpoints. The release includes breaking changes to method signature…
Cloudflare introduced Digital Experience Monitoring (DEX) to provide visibility into device, network, and application performance for Zero Trust organizations. DEX is available on all Cloudflare Zero …
Cloudflare launched an account-level 'enforce DNS-only' feature allowing users to bypass reverse proxy for all zones simultaneously via API. This removes Cloudflare protections (DDoS, WAF, caching) an…
Cloudflare Queues now exposes granular metrics—backlog size, consumer concurrency, and message operations—via GraphQL Analytics API. Users can query real-time or aggregated data programmatically or th…
Cloudflare launched Cache Response Rules, enabling users to modify `Cache-Control` directives, cache tags, and strip headers like `ETag` or `Set-Cookie` from origin responses before caching. Rules app…
Cloudflare introduced Instant Bank Payments via Link, allowing US-based self-serve accounts to pay directly from bank accounts during checkout. The feature integrates with existing Link payment method…
Cloudflare added support for connecting Hyperdrive to private databases using Workers VPC, enabling secure, non-public internet access with TLS verification and reusable VPC services. Users can config…
Cloudflare announced general availability of Gateway Authorization Proxy and hosted PAC files for all plan types. The new proxy endpoints use Cloudflare Access authentication to enforce identity-aware…
Cloudflare Digital Experience Tests now support testing applications protected by Cloudflare Access or third-party authentication, with secrets managed via Cloudflare Secret Store. Enhanced configurat…
Q1 2026 saw a surge in government-directed internet shutdowns in Uganda, Iran, and the Republic of Congo, alongside disruptions from power outages, military strikes on cloud infrastructure in the Midd…
Cloudflare introduced a new speed test feature in its Cloudflare One Client, allowing IT teams to remotely measure internet speed, latency, and network quality metrics directly to Cloudflare's edge. T…
Cloudflare’s Digital Experience (DEX) now shows dashboard alerts when Internet outages or traffic anomalies may impact a Cloudflare One Client device based on location or network. The data is sourced …
Cloudflare launched an account-level setting called enforce_dns_only that disables reverse proxy across all zones, routing traffic directly to origin IPs. This removes all proxy-based protections like…
Cloudflare Queues now provides realtime backlog metrics through its dashboard, REST API, JavaScript API, and GraphQL Analytics API. Three new fields and a metrics object are exposed after message cons…
Cloudflare’s DLP now allows administrators to create, view, and manage detection entries as standalone objects outside of profiles. This change simplifies administration and enables reuse of detection…
Cloudflare updated its dashboard to let users access the Support Portal directly from the global navigation header, bypassing the previous dropdown menu. The change aims to reduce friction when seekin…
Cloudflare introduced a new predefined Data Loss Prevention (DLP) profile that detects PII records containing at least three unique personal data types in close proximity, reducing false positives fro…
Cloudflare introduced Resource Tagging in public beta, allowing users to attach custom key-value metadata to a wide range of resources (e.g., zones, Workers, R2 buckets) and query them with advanced f…
Cloudflare released updates to its WAF managed rules, refining SQL injection (SQLi) detection by merging and renaming existing rules to include '- Body' suffixes. The changes aim to enhance attack pat…
Cloudflare introduced a unified investigation workspace in Brand Protection to consolidate analyst workflows into a single view, replacing fragmented query-based navigation. The change streamlines por…
Cloudflare now supports versioning for Cache Response Rules, allowing teams to test response-phase cache settings in staging before promoting them to production. Previously, these rules applied global…
Cloudflare now returns structured JSON and Markdown responses for its generated 5xx errors (500, 502, 504, 520-526), aligning with RFC 9457 and including Retry-After headers for retryable codes. The u…
Cloudflare introduced the AI Security Suite, a unified platform to secure AI interactions across workforce tools and public-facing applications. It addresses shadow AI, model abuse, agent access, and …
In 2026, cybersecurity CEOs from 10 leading vendors warn that AI will intensify both attacks and defenses, with autonomous agents and AI-driven social engineering becoming dominant threats. Defenders …
Cloudflare introduced a unified platform to detect and block phishing threats across email, SMS, social media, instant messaging, and collaboration apps using ML-powered analysis and Zero Trust servic…
Cloudflare is positioning its Zero Trust Network Access (ZTNA) service as a modern alternative to traditional VPNs, leveraging its SASE platform to improve security, performance, and user experience. …
Cloudflare introduced official SDKs for Go, TypeScript, and Python to simplify API integration, complementing existing cURL examples. The libraries enable language-specific syntax for easier adoption …
Cloudflare introduced Remote Browser Isolation as an add-on for Zero Trust Pay-as-you-go and Enterprise plans, executing active webpage content in a secure isolated browser to protect against zero-day…
Cloudflare now generates Zero Trust Network Session Logs for all traffic proxied through Cloudflare Gateway, including previously unsupported on-ramps like proxy endpoints and Browser Isolation egress…
Cloudflare launched tf-migrate, a CLI tool that automates migrating Terraform configurations from Provider v4 to v5 by handling resource renames, attribute transformations, and moved block generation.…
Cloudflare announced Immerse, a roadshow event in Minneapolis on April 23, 2026, targeting security and IT leaders to discuss Zero Trust, SASE, DDoS, and AI modernization. The event highlights Cloudfl…
Cloudflare released Go SDK v6.10.0 with significant breaking changes driven by OpenAPI updates, including removals and restructurings across multiple services like AI Search, IAM, and Stream. New serv…
Cloudflare introduced organization-level audit logs in Audit Logs v2, allowing Org Admins to retrieve audit events for organization-level actions via the API. This update is separate from account-leve…
Cloudflare introduced usage-based billing for several products, shifting from prepaid flat fees to postpaid charges based on actual consumption during the previous billing period. This affects custome…
Cloudflare announced comprehensive WebAssembly error recovery for Rust Workers, addressing fatal panics and aborts that previously poisoned Worker instances and caused cascading failures. The update i…
Cloudflare announced Immerse, its premier roadshow event in Montreal on April 22, 2026, focused on application, security, and network modernization. The event targets security, IT, and digital leaders…
Cloudflare introduced automated table maintenance for R2 Data Catalog, including compaction and snapshot expiration for Apache Iceberg tables stored in R2. Compaction combines small files into larger,…
Cloudflare made custom dashboards generally available to all customers, enabling personalized views using over 100 GraphQL datasets and raw Log Explorer data. Users can now consolidate metrics from mu…
Cloudflare’s R2 Data Catalog now automatically removes unreferenced data files during snapshot expiration, not just Iceberg metadata. Previously, only metadata files were cleaned up, leaving stale dat…
Cloudflare updated Wrangler’s configuration system to support both JSON (including JSONC) and TOML formats as of Wrangler v3.91.0, with JSONC recommended for new projects. The configuration file serve…
Cloudflare introduced subrequest merging in Logpush, an opt-in feature that aggregates multiple log entries from Worker subrequests into a single parent request log line. By default, each subrequest g…
Cloudflare introduced a Hibernation WebSocket API for Durable Objects, enabling WebSocket servers to hibernate when idle without disconnecting clients, reducing costs by avoiding billable duration cha…
Cloudflare argues that the traditional 'bots vs. humans' distinction is outdated as AI agents and automated clients increasingly mimic human behavior, disrupting the implicit balance between publisher…
Cloudflare Workflows now supports additional context in step.do() callbacks and allows returning ReadableStream for larger step outputs. The step.do() callback receives a context object with new prope…
Cloudflare introduced a Network session analytics dashboard in Cloudflare One to provide visibility into Zero Trust traffic patterns. The dashboard tracks session counts, bandwidth usage, connection i…
Cloudflare introduced a Billable Usage dashboard and Budget alerts for pay-as-you-go customers, enabling daily cost monitoring and spend threshold notifications. The dashboard provides granular, invoi…
Cloudflare introduced a new Network Overview page in its dashboard, serving as a centralized hub for network security and connectivity products. Users can now connect resources via Cloudflare Tunnel, …
Cloudflare’s April 21, 2026 WAF release introduces new detections for critical vulnerabilities, including Apache ActiveMQ RCE (CVE-2026-34197) and Magento 2 unrestricted file uploads, both now blocked…
Cloudflare introduced subrequest merging in Logpush to consolidate multiple subrequest log entries into a single parent log record. Previously, each subrequest generated separate log lines, creating r…
Cloudflare changed WebSocket binary frame delivery in Workers to default to Blob objects instead of ArrayBuffer, aligning with the WebSocket specification and browser behavior. This affects Workers wi…
Cloudflare’s Container logs page now aggregates Worker and Durable Object logs alongside container logs in a single view. This change centralizes log data for containerized applications, enabling easi…
Cloudflare introduced Kimi K2.6, a 1-trillion parameter open-source AI model with a 262,144-token context window, supporting multi-turn tool calling, vision inputs, and structured outputs for agentic …
Cloudflare introduced Workers AI bindings, enabling developers to integrate AI models directly into Workers and Pages Functions via the Cloudflare Developer Platform. Bindings can be configured in the…
Cloudflare introduced Tiered Cache, a feature that reduces origin server requests by organizing its global data centers into a hierarchical topology. Lower-tier edge locations query upper-tier hubs be…
Cloudflare revealed that 93% of its R&D organization (3,683 users) actively used internal AI coding tools over the last 30 days, processing 47.95 million AI requests and driving a 55% increase in merg…
Cloudflare built an AI-native code review system using OpenCode to address bottlenecks in engineering workflows. The system replaces manual reviews with up to seven specialized AI agents (security, pe…
Cloudflare concluded its first Agents Week by unveiling a suite of new primitives and services designed to support the rise of AI agents as a primary workload. The company introduced compute environme…
Cloudflare introduced native Pipelines as a Logpush destination, enabling event ingestion, SQL-based transformation, and delivery to R2 as Iceberg tables, Parquet, or JSON files. Logpush can now route…
Cloudflare released R2 SQL in open beta, a read-only SQL query engine for Cloudflare R2 object storage. The service supports basic SQL operations (SELECT, WHERE, GROUP BY, etc.) and 206 scalar/aggrega…
Cloudflare added Moonshot AI’s Kimi K2.6 model to Workers AI, a 1T-parameter MoE model with 32B active parameters, 262.1k context window, vision, and agentic capabilities. It competes with GPT-5.4 and…
Cloudflare launched a Network session analytics dashboard in Cloudflare One on April 20, 2026, providing visibility into network traffic patterns including geographic distribution, session metrics, pr…
Cloudflare introduced a new Logpush destination option, allowing users to send logs directly to Pipelines for in-flight transformation and storage in R2 as Parquet files or Apache Iceberg tables manag…
Cloudflare added JSON query functions, EXPLAIN FORMAT JSON support, and unpartitioned Iceberg table querying to R2 SQL, its serverless analytics engine for Apache Iceberg tables in R2 Data Catalog. JS…
Cloudflare introduced new AI-focused tools to improve website compatibility with AI agents and crawlers. The Agent Readiness score helps site owners assess how well their sites support AI agents, with…
Cloudflare introduced new AI-focused tools in Radar, including an Agent Readiness score to help site owners assess AI agent compatibility, shared compression dictionaries to improve page load times fo…
Cloudflare introduced the Agent Readiness score to help website owners assess how well their sites support AI agents. The company also revealed support for shared compression dictionaries to improve p…
Cloudflare introduced a new API endpoint `/radar/agent_readiness/summary/{dimension}` to provide AI agent readiness scores across scanned domains, grouped by specified dimensions like 'CHECK'. The API…
Cloudflare introduced a new API endpoint to retrieve the median HTML-to-markdown reduction ratio for AI agent requests over specified date ranges. The endpoint, `/radar/ai/markdown_for_agents/summary`…
Cloudflare introduced 'Markdown for Agents,' a feature enabling real-time HTML-to-Markdown conversion for AI systems via content negotiation headers. When AI agents request pages from Cloudflare-enabl…
Cloudflare announced support for shared compression dictionaries to reduce asset transfer sizes and improve page load speeds, particularly for returning users and slow connections. The technology comp…
Cloudflare launched 'Redirects for AI Training,' a feature that enforces HTTP 301 redirects for verified AI training crawlers (e.g., GPTBot, ClaudeBot) to current content using existing canonical tags…
Cloudflare launched Flagship, a native feature flag service built on OpenFeature, designed to support AI-driven autonomous code deployment. Flagship enables AI agents to write, deploy, and roll out co…
Cloudflare increased its share of the fastest network provider from 40% to 60% in the top 1,000 global networks by December 2025, measured via TCP connection time using Real User Measurements (RUM). T…
Cloudflare launched Agent Memory, a private beta managed service that provides persistent memory for AI agents by extracting, storing, and retrieving contextually relevant information without bloating…
Cloudflare introduced Unweight, a lossless compression system for LLM model weights that reduces size by 15–22% without hardware changes, enabling faster and cheaper inference. By compressing only the…
Cloudflare introduced Redirects for AI Training, a feature that enforces existing `<link rel="canonical">` tags as 301 redirects for verified AI training crawlers. When such crawlers request a page wi…
Cloudflare Radar introduced three new AI Insights features: a widget tracking adoption of AI agent standards (filterable by domain and available via API), a savings gauge showing bandwidth/token reduc…
Cloudflare introduced Smart Tiered Cache optimizations for public cloud origins, enabling higher cache HIT rates and reduced origin load by selecting optimal upper-tier data centers based on cloud reg…
Cloudflare introduced AI Crawl Control tools to optimize websites for AI agents in the 'agentic Internet.' The Content Format chart in the Metrics tab shows AI-requested content types versus origin-se…
Cloudflare now redirects verified AI training crawlers to canonical URLs when they request deprecated or duplicate pages. Enabled via AI Crawl Control, this feature uses existing canonical tags to iss…
Cloudflare introduced the Agent Readiness score, a tool to help website owners assess and improve their site’s compatibility with AI agents. The score evaluates four dimensions: discoverability (robot…
Cloudflare deprecated the legacy `env.AI.autorag()` binding for AI Search in favor of new `ai_search` and `ai_search_namespaces` bindings. The new bindings require updated Wrangler configurations, Typ…
Cloudflare introduced hybrid search for its AI Search product, enabling parallel execution of vector and keyword search methods with merged results. The feature requires keyword search to be enabled a…
Cloudflare introduced relevance boosting for its AI Search product, allowing users to bias search results toward documents with specific metadata characteristics. The feature re-ranks retrieved result…
Cloudflare introduced an Artifacts Workers binding that enables direct repo operations (create, inspect, fork, delete) from Workers via a typed binding. Developers configure the binding in wrangler.js…
Cloudflare introduced Git protocol support for its Artifacts repositories, enabling standard Git-over-HTTPS operations like clone, fetch, pull, and push. Repositories are accessible via HTTPS remotes …
Cloudflare introduced three key updates: one-click Rules Templates for faster rule configuration, Regionalized Generic Tiered Cache to improve cache hit ratios by routing content consistently within r…
Cloudflare announced significant performance improvements to its Workers AI platform, including a 3x speed increase for Moonshot’s Kimi K2.5 model. The company introduced a disaggregated prefill-decod…
Cloudflare launched AI Gateway and Workers AI as a unified inference layer, allowing developers to access over 70 models from 12+ providers (including OpenAI, Anthropic, Google, and others) through a …
Cloudflare launched AI Search, a new plug-and-play search primitive for AI agents, replacing AutoRAG. It enables hybrid search combining vector and keyword (BM25) retrieval, built-in storage and vecto…
Cloudflare will allow users to create and bill PlanetScale Postgres and MySQL databases directly from the Cloudflare dashboard and API starting next month, integrating billing into Cloudflare accounts…
Cloudflare introduced significant changes to its AI Search service, including built-in storage and vector indexing for new instances, eliminating the need for external R2 buckets or data sources. New …
Cloudflare introduced hybrid search and relevance boosting for its AI Search product. Hybrid search merges vector-based semantic search with BM25 keyword search, allowing users to configure tokenizers…
Cloudflare introduced Email Address Obfuscation, a feature that automatically hides email addresses on web pages from bots while keeping them visible and clickable for humans. The feature works by rep…
Cloudflare launched Email Sending in public beta as part of its Email Service, enabling bidirectional email communication for agents. The service allows agents to receive, process, and reply to emails…
Cloudflare introduced the Access App Launcher, a centralized dashboard where users can open all authorized applications from a single interface. The feature is accessible via a unique team domain (e.g…
Cloudflare introduced Independent MFA, a feature allowing organizations to enforce multi-factor authentication (MFA) directly within its Zero Trust Access service without relying on third-party identi…
Cloudflare launched Artifacts in private beta, introducing a versioned filesystem with Git access for Workers, APIs, and Git-compatible workflows. The service enables creation of tens of millions of r…
Cloudflare updated its Logpush dataset documentation to clarify field availability across log categories, subscription plans, and access methods. The most significant change is the explicit distinctio…
Cloudflare has expanded its Logpush dataset offerings to include detailed fields for `firewall_events`, enabling users to capture granular security and traffic data from Cloudflare’s Firewall products…
Cloudflare has expanded the dataset fields available for HTTP requests in its Logpush service, adding detailed bot management, fraud detection, and security-related metadata. The update introduces new…
Cloudflare has introduced advanced settings for its Data Loss Prevention (DLP) profiles, enabling more granular control over sensitive data detection. The key changes include configurable match count …
Cloudflare Access now supports securing web applications as an identity-aware proxy, verifying user identity before granting access based on policies tied to existing identity providers, device postur…
Cloudflare has expanded its GraphQL API documentation to include a new getting-started guide for its Analytics GraphQL API. The guide provides step-by-step instructions for authentication, querying ba…
Cloudflare has updated the operational limits for its Workflows product, a serverless workflow automation tool. The most significant changes include increased default and configurable limits for compu…
Cloudflare introduced a 'Human in the Loop' feature for its Browser Run service, enabling temporary human intervention in browser automation workflows. The feature allows a human operator to take cont…
Cloudflare introduced session recording for its Browser Run service, enabling lightweight debugging of browser automation scripts by capturing DOM changes, mouse/keyboard events, and page navigation a…
Cloudflare introduced WebMCP, a browser API enabling AI agents to directly discover and execute structured tools exposed by websites, replacing traditional screenshot-analyze-click automation loops. T…
Cloudflare launched a beta version of its Registrar API, enabling programmatic domain search, availability checks, and registration directly within AI code editors, deployment pipelines, and agent-dri…
Cloudflare has launched Agent Lee, an in-dashboard AI assistant designed to revolutionize how users interact with its platform by enabling natural language commands to perform complex tasks. Agent Lee…
Cloudflare introduced Project Think, a next-generation Agents SDK featuring durable execution, sub-agents, persistent sessions, and sandboxed code execution to build long-running AI agents. The platfo…
Cloudflare renamed its Browser Rendering product to Browser Run and introduced major enhancements to support AI agents interacting with the web. The most significant change is the direct exposure of t…
Cloudflare announced Workflows v2, a major upgrade to its durable execution engine for multi-step applications, increasing scalability limits from 4,500 to 50,000 concurrent instances and from 100 to …
Cloudflare has introduced an experimental voice pipeline for its Agents SDK, enabling real-time voice interactions without requiring a separate voice framework. The new @cloudflare/voice package allow…
Cloudflare introduced a new container lifecycle architecture for its Container platform, fundamentally changing how containerized applications are deployed, scaled, and managed. The most significant c…
Cloudflare introduced support for controlling its Browser Rendering service via the Model Context Protocol (MCP) using the chrome-devtools-mcp package. This allows AI coding agents to automate browser…
Cloudflare introduced new `wrangler browser` commands to manage Browser Rendering sessions directly from the command line via Wrangler. The commands allow developers to create, close, list, and view b…
Cloudflare has introduced independent multi-factor authentication (MFA) for its Access applications, enabling enforcement of MFA policies without relying on third-party identity providers. This change…
Cloudflare introduced three new features for Browser Run—Live View, Human in the Loop, and Session Recordings—to enhance browser automation visibility and reliability. Live View provides real-time mon…
Cloudflare introduced regional and jurisdictional placement controls for its Containers product, allowing users to specify where their containers run. The update enables geographic constraints using r…
Cloudflare has improved the consistency of last seen timestamps for Cloudflare One Client devices in its dashboard. This change ensures IT teams receive more reliable and synchronized data about the m…
Cloudflare raised key limits for its Workflows service on April 15, 2026, increasing the concurrency limit for running instances from 10,000 to 50,000, the instance creation rate from 100 to 300 per s…
Cloudflare’s Browser Run now supports WebMCP, a new browser API from Google Chrome that enables AI agents to discover and execute structured website tools directly. This eliminates unreliable screensh…
Cloudflare introduced redesigned builders for Gateway policies and self-hosted Access applications in its Cloudflare One dashboard, streamlining workflows with clearer states, inline policy creation, …
Cloudflare has renamed its Browser Rendering product to Browser Run, expanding its capabilities beyond rendering to include full browser session execution, AI-driven automation, and human-in-the-loop …
Cloudflare’s AI co-pilot, Agent Lee, now supports write operations and generative UI, enabling users to make natural language configuration changes and visualize real-time account data. Write operatio…
Cloudflare has made Privacy Proxy metrics queryable through its GraphQL Analytics API, replacing the previous default method for accessing observability data. Four new GraphQL nodes now provide aggreg…
Cloudflare has added new fields to its Logpush datasets, including TenantID for Gateway and Zero Trust logs and Firewall for AI security metrics. The TenantID field now appears in Gateway DNS, HTTP, a…
Cloudflare has introduced a new scannable format for its API credentials, replacing older unprefixed strings with prefixed tokens that include a 40-character identifier and a checksum. The new format …
Cloudflare Mesh introduces post-quantum encrypted networking to privately route traffic between servers, laptops, and phones without VPNs or bastion hosts. Every enrolled device or node receives a pri…
Cloudflare introduced CIDR route management for its Cloudflare Mesh nodes, enabling devices on a Mesh network to reach other hosts on the local subnet behind a node—such as servers, databases, printer…
Cloudflare has introduced high availability (HA) support for its Mesh node deployments, enabling multiple replicas of a single node to run in active-passive mode. All replicas share the same node iden…
Cloudflare has introduced network policies in Cloudflare One to control TCP and UDP traffic between users and network destinations, enabling granular allow or block actions based on IP addresses, port…
Cloudflare introduced device posture checks as part of its Zero Trust framework, enabling stricter access controls for protected applications and network resources. Users can now configure policies re…
Cloudflare introduced VPC Networks for Workers, enabling direct access to private network services without pre-registering individual hosts or ports. Unlike VPC Services, which require separate bindin…
Cloudflare introduced VPC Services as a core component of Workers VPC, enabling secure access to private network resources from Workers via Cloudflare Tunnel. Workers can now bind to specific VPC Serv…
Cloudflare has fully integrated the Model Context Protocol (MCP) into its enterprise operations, deploying agentic workflows across engineering, product, sales, marketing, and finance teams to drive e…
Cloudflare has introduced managed OAuth for Cloudflare Access, enabling agents (AI tools, scripts, or automated systems) to authenticate and access internal apps protected by Access without manual wor…
Cloudflare introduced security updates to address risks in agentic AI systems, including credential leaks, user impersonation, and elevation of privilege, which can cause denial of service, data loss,…
Cloudflare introduced Cloudflare Mesh, a new private networking solution designed to securely connect autonomous AI agents, developers, and services to private infrastructure. Mesh integrates with Clo…
Cloudflare announced Immerse NYC, a roadshow event on April 14, 2026, in New York City, targeting security, IT, and digital leaders. The event focuses on Zero Trust, SASE, DDoS, application security, …
Cloudflare introduced a new integration allowing Puppeteer, a Node.js library for browser automation, to connect directly to its Browser Rendering service via the Chrome DevTools Protocol (CDP). This …
Cloudflare has integrated Playwright with its Browser Rendering service, enabling developers to automate browser tasks programmatically via the Chrome DevTools Protocol (CDP) from any Node.js environm…
Cloudflare has launched Cloudforce One, its Threat Intelligence Platform (TIP), which aggregates and correlates threat data from Cloudflare’s global network telemetry to provide actionable intelligenc…
Cloudflare introduced support for the Chrome DevTools Protocol (CDP) via new `/devtools` endpoints, enabling persistent browser sessions, tab management, and remote browser control through WebSocket a…
Cloudflare has introduced account-level Data Loss Prevention (DLP) settings in Cloudflare One, enabling advanced configurations such as OCR, AI context analysis, and payload masking to be managed cent…
Cloudflare introduced Cloudflare Mesh, a private networking solution designed to secure AI agent connections to internal infrastructure without exposing data to the public internet. The product enable…
Cloudflare launched Cloudflare Mesh, a post-quantum encrypted mesh networking solution that enables private, direct traffic routing between servers, laptops, and phones without VPNs or bastion hosts. …
Cloudflare and Wiz announced a partnership to integrate Cloudflare’s AI Security for Apps with Wiz’s AI Application Protection Platform, enabling organizations to discover, inspect, and secure AI endp…
Cloudflare changed the Email Address Obfuscation decode script to load with the `defer` attribute, making it non-render-blocking. This improves page loading performance and Core Web Vitals for all zon…
Cloudflare introduced new Wrangler CLI commands for managing Browser Rendering sessions directly from the terminal. Developers can now create, close, list, and view browser sessions using commands lik…
Cloudflare introduced granular OAuth consent and management features, allowing users to select specific accounts for third-party application access instead of granting blanket permissions. The update …
Cloudflare Radar’s shareable widgets now include a ‘generate citation’ feature, allowing users to export data in BibTeX, APA, MLA, Chicago, and RIS formats. This change simplifies referencing Radar da…
Cloudflare has added native dashboard support for configuring Logpush jobs to Google BigQuery, eliminating the previous requirement to use the API. Users can now create and manage BigQuery Logpush des…
Cloudflare introduced configurable payload log masking for Data Loss Prevention (DLP) to let incident response teams control how sensitive data appears in logs. Previously, all DLP payload logs used a…
Cloudflare has introduced VPC Networks and Cloudflare Mesh support in public beta for its Workers platform, enabling direct access to private networks without pre-registering individual hosts or ports…
Cloudflare introduced outbound handlers for its Sandbox environment, enabling developers to intercept, modify, and control HTTP/HTTPS traffic leaving sandboxes. The feature allows granular control ove…
Cloudflare introduced outbound traffic interception capabilities for its Containers platform, allowing developers to programmatically control, modify, and secure HTTP/HTTPS egress traffic from contain…
Cloudflare introduced webhook integrations for its Cloud Access Security Broker (CASB) within Cloudflare One, enabling automated forwarding of posture finding instances to external systems like chat p…
Cloudflare has introduced a new capability within its Cloudflare One platform to manage security findings detected in SaaS and cloud applications, including users, data at rest, and configuration sett…
Cloudflare has introduced Link Aggregation Group (LAG) support for its Cloudflare One Appliance, allowing users to bundle multiple physical LAN ports into a single logical interface. This feature incr…
Cloudflare now allows Enterprise customers to use their own Certificate Authorities (CAs) for mutual TLS (mTLS) authentication, expanding beyond its default CA. This change enables organizations with …
Cloudflare introduced a centralized organization setup feature requiring Enterprise plan users to create and manage organizations, assign accounts, and invite members with implicit Super Administrator…
Cloudflare has expanded its changelog system by introducing granular RSS feeds for tracking updates across specific product areas, including Application performance, Application security, Cloudflare O…
Cloudflare has introduced a significant evolution of its Wrangler CLI tool, now rebranded as 'cf', to unify access to its entire API surface for both human developers and AI agents. The most critical …
Cloudflare has announced the general availability of its Sandboxes and Cloudflare Containers, a persistent, isolated environment designed to safely run AI agents and development workloads. The platfor…
Cloudflare introduced Durable Object Facets, a new feature in open beta for its Workers platform, enabling dynamic loading and instantiation of Durable Object classes within Dynamic Workers. This solv…
Cloudflare has introduced outbound Workers for its Sandboxes and Containers, enabling programmatic egress proxies that enhance security, observability, and authentication for agentic workloads. The ne…
Cloudflare has announced the general availability of its Containers and Sandbox products, marking a significant expansion of its Workers platform. Containers now enable the execution of resource-inten…
Cloudflare has introduced significant enhancements to its Outbound Workers for Sandboxes and Containers, enabling zero-trust credential injection, TLS interception, allow/deny host lists, and dynamic …
Cloudflare has launched 'Agents Week,' a dedicated initiative to build infrastructure for the emerging agentic era of the Internet, where AI-driven agents will perform tasks autonomously on behalf of …
Cloudflare has integrated the Chrome DevTools Protocol (CDP) into its Browser Rendering service, enabling direct access to low-level browser automation capabilities. This change allows any CDP-compati…
Cloudflare API tokens now follow a standardized format that secret scanning tools can automatically detect when leaked in public repositories or code. This change enables immediate detection of expose…
Cloudflare has relaxed the simultaneous open connections limit for its Workers platform, reducing constraints on connection management. Previously, each Worker invocation was capped at six open connec…
Cloudflare has introduced CASB (Cloud Access Security Broker) webhooks in its Cloudflare One platform, enabling security teams to automatically route CASB posture findings to external systems such as …
Cloudflare has launched AI Search, a fully managed retrieval-augmented generation (RAG) service designed to enable developers to build scalable, context-aware AI applications without managing infrastr…
Cloudflare has developed an automated tool to reverse-engineer malicious Linux BPF (Berkeley Packet Filter) socket programs used by malware authors to create stealthy backdoors. These BPF programs, of…
The Cloudflare Workers Request interface, part of the Fetch API, has been updated to enhance developer control over HTTP request handling within Cloudflare’s serverless platform. The most significant …
Cloudflare has introduced Request Header Transform Rules, enabling users to modify HTTP request headers sent to origin servers. This feature allows setting header values to literal strings or dynamic …
Cloudflare has introduced four new Workers AI models for its AI Search service, expanding its text generation and embedding capabilities. The additions include GLM-4.7-Flash, a lightweight model from …
Cloudflare has introduced automated real-time alerts and daily digests for its Threat Events feature, enabling users to subscribe to notifications based on custom saved views. This update allows secur…
Cloudflare has introduced a new feature for its User Risk Scoring system, integrating Gateway DNS traffic patterns to automatically elevate a user's risk score when they visit high-risk or malicious d…
Cloudflare has introduced CSS content selectors for its AI Search feature, enabling precise control over which parts of crawled web pages are indexed. Users can now specify CSS selectors paired with U…
Cloudflare has accelerated its post-quantum cryptography (PQC) roadmap, targeting full post-quantum security—including authentication—by 2029, a significant shift from prior timelines. The urgency ste…
Cloudflare’s Logpush feature delivers logs in near real-time batches, with no minimum batch size and potential delivery frequencies exceeding once per minute. This enables faster access to smaller log…
Cloudflare has released a General Availability (GA) version 2026.3.851.0 of its Cloudflare One Client for Windows, addressing critical stability and connectivity issues. The update fixes multiple tunn…
Cloudflare and GoDaddy announced a strategic partnership to integrate Cloudflare’s AI Crawl Control into GoDaddy’s hosting platform, giving website owners visibility and control over AI crawlers. The …
Cloudflare has updated its Workers runtime to automatically send a reciprocal Close frame when receiving a Close frame from a WebSocket peer, aligning with the WebSocket specification and standard bro…
Cloudflare introduced Triage Status Tracking for User Submissions in its Email Security product, enabling SOC teams to track, manage, and prioritize user-submitted emails directly within the Cloudflar…
Cloudflare has introduced Link Aggregation Control Protocol (LACP) support for its Cloudflare One Appliance, enabling users to bundle up to six physical LAN ports into a single logical interface. This…
Cloudflare has introduced a dashboard-based solution for managing mutual TLS (mTLS) and Bring Your Own Certificate Authority (BYO CA) configurations, eliminating the previous requirement to use the Cl…
Cloudflare’s latest Web Application Firewall (WAF) managed ruleset release, dated April 7, 2026, introduces critical security enhancements to address three high-severity vulnerabilities. The update ad…
Cloudflare has launched a redesigned 'Get Help' Support Portal to streamline customer support interactions. The new portal replaces a complex, multi-step navigation system with a simplified, personali…
Cloudflare has reinforced its position as a unified connectivity cloud platform, emphasizing its ability to connect, protect, and build across users, applications, AI agents, and networks. The company…
Cloudflare has launched a new Organizations feature in beta, designed to simplify the management of multiple Cloudflare accounts for enterprise customers. Historically, enterprises have segmented thei…
Cloudflare has introduced DANE (DNS-based Authentication of Named Entities) support for MX deployments in its Email Security service, enabling DNSSEC-backed certificate verification for regional MX ho…
Cloudflare has introduced a new field to its Gateway DNS Logpush dataset, enhancing the granularity of DNS query logging for users. The update adds a previously unspecified metric, though the exact na…
Cloudflare has launched Organizations in public beta for enterprise customers, introducing a top-level container to centrally manage multiple Cloudflare accounts, members, analytics, and shared polici…
Cloudflare has partnered with Google to integrate the Gemma 4 26B A4B model into its Workers AI platform. This Mixture-of-Experts (MoE) model features 26 billion total parameters with only 4 billion a…
Cloudflare reports that 32% of its network traffic now originates from automated sources, with AI crawlers accounting for 80% of self-identified AI bot traffic. Unlike human users, AI agents generate …
Cloudflare announced its Immerse roadshow event in Houston on April 2, 2026, targeting security, IT, and digital leaders. The event will focus on application, security, and network modernization, incl…
Cloudflare has introduced native support for Google Cloud BigQuery as a destination for its Logpush service, enabling direct streaming of Cloudflare logs to BigQuery. This integration allows users to …
Cloudflare has released the General Availability (GA) version 2026.3.846.0 of its Cloudflare One Client for Linux, marking the first stable Linux release. This update includes minor fixes and improvem…
Cloudflare has introduced automatic retry functionality at the gateway level for its AI Gateway product. This feature allows requests to be automatically retried when upstream providers return errors,…
Cloudflare has introduced several incremental updates across its product ecosystem, primarily focused on enhancing developer experience, improving reliability, and expanding observability capabilities…
Cloudflare has introduced several incremental updates and improvements across its product ecosystem, primarily focused on enhancing developer experience, operational efficiency, and data visibility. T…
Cloudflare has introduced several incremental updates across its product ecosystem, primarily focused on improving user experience, reliability, and developer tooling. The most significant changes inc…
Cloudflare has released a General Availability (GA) version 2026.3.846.0 of its Cloudflare One Client for Windows, marking a stable milestone for the product. This update includes minor fixes and impr…
Cloudflare has announced a series of incremental updates and improvements across multiple products, primarily focused on enhancing usability, reliability, and developer experience. The most significan…
Cloudflare has rolled out several incremental updates across its product ecosystem, primarily focused on improving usability, reliability, and developer experience. The most significant changes includ…
Cloudflare has released a General Availability (GA) version 2026.3.846.0 of its Cloudflare One Client for macOS, now available on the stable releases downloads page. The update includes minor fixes an…
Cloudflare has enhanced its Cloudflare One Secure Web Gateway with new identity-based policy controls that allow organizations to filter outbound traffic at the user identity level. The update introdu…
Cloudflare has launched EmDash, a new open-source content management system (CMS) designed as a modern, serverless successor to WordPress. Built entirely in TypeScript and powered by Astro, EmDash add…
Cloudflare has released the results of its 2024 independent privacy examination for its 1.1.1.1 public DNS resolver, confirming that its core privacy commitments remain unchanged and validated. The ex…
Cloudflare has released version 0.3.3 of the `@cloudflare/codemode` package, a tool designed to enable code execution within Cloudflare's edge network. This update, published a day ago, marks a minor …
Cloudflare has released a new package called @cloudflare/shell, a command-line interface (CLI) tool designed to interact with Cloudflare’s services. The package, currently at version 0.3.1, is lightwe…
Cloudflare has introduced **resolver policies** for its Enterprise-grade Gateway DNS service, enabling organizations to route DNS queries to custom resolvers instead of defaulting to Cloudflare’s publ…
Cloudflare has refreshed the user interface for its Access authentication logs and Gateway activity logs (DNS, Network, and HTTP) to enhance usability and customization. The updated UI introduces flex…
Cloudflare has introduced several significant updates across its product ecosystem, primarily focused on developer tools, security, and network telemetry. The most impactful changes include expanded l…
Cloudflare has introduced a new command namespace, `wrangler ai-search`, within its Wrangler CLI to enable users to create, manage, and search AI Search instances directly from the command line. The u…
Cloudflare has introduced Deploy Hooks for Workers Builds, enabling automated build triggers via HTTP POST requests to unique URLs tied to specific branches. This feature allows developers to initiate…
Cloudflare has introduced several significant updates across its product ecosystem, primarily focused on enhancing developer experience, security, and integration capabilities. The most impactful chan…
On April 1, 2026, Cloudflare introduced several significant updates across its product ecosystem, primarily centered on developer tools, security, and network analytics. The most impactful changes inc…
Cloudflare has introduced several significant updates across its product ecosystem, primarily centered on enhancing developer experience, security capabilities, and integration between its services. T…
Cloudflare has introduced several significant updates across its product ecosystem, primarily focused on developer tools, security, and network telemetry. The most impactful changes include expanded l…
Cloudflare has introduced local development support for all Wrangler commands related to Workflows, enabling developers to manage Workflows entirely within a local environment using the `--local` flag…
Cloudflare has introduced three new properties on the `request.cf` object in its Workers platform, enabling real-time Layer 4 transport telemetry for client connections. These properties—`clientTcpRtt…
Cloudflare has introduced several incremental updates across its product ecosystem, primarily focused on improving usability, reliability, and developer experience. The most significant changes includ…
Cloudflare Radar’s Routing section has been expanded into a dedicated, three-part hub with new sub-pages and widgets. The Overview page now aggregates routing statistics, IP address space trends, BGP …