WAF - WAF Release - 2026-07-21
UpdateUnverifiedAdded Sep 24, 2026
This release introduces new rules for vulnerabilities in Adobe ColdFusion, Next.js, WordPress alongside updates to existing rules thereby providing enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS).
Topics: Security, Developer tools
More Cloudflare developer platform releases
Every Cloudflare developer platform release| Date | Release | Type |
|---|---|---|
| Jul 21 | Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.880.0)unverified GA | GA |
| Jul 21 | Cloudflare One Client - Cloudflare One Client for macOS (version 2026.6.880.0)unverified GA | GA |
| Jul 21 | Cloudflare One Client - Cloudflare One Client for Linux (version 2026.6.880.0)unverified GA | GA |
| Jul 21 | Cloudflare Fundamentals - Account Role API deprecatedunverified Deprecation | Deprecation |
| Jul 21 | Sandbox SDK - Run Devin on Cloudflare using Devin Outpostsunverified Update | Update |
| Jul 21 | SSL/TLS - Faster and more secure TLS handshakes to your origins, automaticallyunverified Update | Update |
| Jul 22 | Agents, Workers - Agents SDK reduces MCP schema conversion, adds exposure controls for MCP in Think and Code Mode SDK adds direct host APIsunverified Update | Update |
| Jul 20 | Access - Browser-based login for plaintext HTTP private applicationsunverified Update | Update |
Also shipped on Jul 21, 2026
Cloudflare in July 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.