WAF - WAF Release - 2026-09-22
UpdateUnverifiedAdded Sep 24, 2026
This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.
Topics: Observability, Developer tools
More Cloudflare developer platform releases
Every Cloudflare developer platform release| Date | Release | Type |
|---|---|---|
| Sep 22 | Access - Automatically manage inactive Access service tokensunverified Update | Update |
| Sep 22 | Cloudflare One, Access - Private MCP server support for MCP server portalsunverified Update | Update |
| Sep 22 | Rules - concat() now supports up to 32 argumentsunverified Update | Update |
| Sep 22 | WAF - WAF Release - Scheduled changes for 2026-09-29unverified Beta | Beta |
| Sep 22 | Workers - Workers Builds now supports Cursor Originunverified Preview | Preview |
| Sep 22 | Workers - Test every pull request in an isolated environment with Worker Previewsunverified Preview | Preview |
| Sep 23 | Durable Objects - Durable Object name search now supports 128 charactersunverified Update | Update |
| Sep 23 | Gateway, Cloudflare One - Traffic Destination selector in Gateway policiesunverified Update | Update |
Also shipped on Sep 22, 2026
Cloudflare in September 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.