Skip to content

WAF - WAF Release - 2026-08-07

UpdateUnverifiedAdded Sep 24, 2026

This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule. Key Findings CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen.

Topics: Security

Cloudflare's release notes

More Cloudflare developer platform releases

Every Cloudflare developer platform release

Also shipped on Aug 7, 2026

Cloudflare in August 2026

Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.

New releases by email

Tuesday mornings: the week's data, AI and developer-tools releases, only in weeks when something shipped.

Double opt-in. Unsubscribe any time.