WAF - WAF Release - 2026-08-07
UpdateUnverifiedAdded Sep 24, 2026
This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule. Key Findings CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen.
Topics: Security
More Cloudflare developer platform releases
Every Cloudflare developer platform release| Date | Release | Type |
|---|---|---|
| Aug 7 | AI Gateway, Workers AI - Workers AI and AI Gateway unify model access and billingunverified Pricing | Pricing |
| Aug 7 | Hyperdrive - MySQL support in Hyperdrive is now generally availableunverified GA | GA |
| Aug 7 | Hyperdrive - Restart a Hyperdrive configuration from the dashboardunverified Update | Update |
| Aug 7 | Load Balancing - Load Balancing health notifications now resolve automaticallyunverified Update | Update |
| Aug 7 | Cloudflare Mesh, Cloudflare One - Container image for Cloudflare Meshunverified Update | Update |
| Aug 7 | Radar - AS-level connectivity and upstream providers on Cloudflare Radarunverified Update | Update |
| Aug 7 | Radar - Radar Researcher beta and WebMCP support now availableunverified Beta | Beta |
| Aug 7 | Sandbox SDK - Sandbox SDK 1.0 preview on @nextunverified Preview | Preview |
Also shipped on Aug 7, 2026
Cloudflare in August 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.