WAF - WAF Release - 2026-07-14
UpdateUnverifiedAdded Sep 24, 2026
This release introduces new rules targeting critical infrastructure vulnerabilities. These include an unauthenticated memory disclosure flaw in Citrix NetScaler ADC and Gateway (CVE-2026-8451) and a high-severity pre-authentication remote code execution (RCE) vulnerability in Progress Kemp LoadMaster (CVE-2026-8037).
Topics: Security, Observability
More Cloudflare developer platform releases
Every Cloudflare developer platform release| Date | Release | Type |
|---|---|---|
| Jul 14 | Cloudflare Web Analytics - Improved reliability for account-wide Web Analytics dashboardsunverified Update | Update |
| Jul 14 | Workers - Platforms can now create Temporary Accounts via the Cloudflare APIunverified Preview | Preview |
| Jul 15 | Gateway, DNS - Internal DNS is now generally availableunverified GA | GA |
| Jul 15 | Email Service, Queues - Subscribe to Email Sending events with Queuesunverified Update | Update |
| Jul 15 | KV - Deprecate legacy Workers KV namespace API routesunverified Deprecation | Deprecation |
| Jul 13 | Agents, Workers - Agents can respond to MCP elicitation requestsunverified Update | Update |
| Jul 13 | Bots - Precursor introduces session-based bot detectionunverified Update | Update |
| Jul 13 | Cloudflare Fundamentals - Origin Content Signals for Markdown for Agentsunverified Update | Update |
Also shipped on Jul 14, 2026
Cloudflare in July 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.