Cloudflare AI
AI Gateway now provides a new REST API allowing users to call any AI model from various providers through a unified interface, with four specific endpoints available for different functionalities.
AI Gateway now provides a new REST API allowing users to call any AI model from various providers through a unified interface, with four specific endpoints available for different functionalities.
The Cloudflare One Client for Linux has been officially released with a new user interface, improved functionality including a right-click context menu and built-in captive portal login, as well as added support for RHEL 9. However, there are known issues regarding registration and split tunnel configuration management.
The Cloudflare AI WAF release on 2026-05-11 includes enhancements to existing rules for improved detection of web attacks and introduces a new rule for Remote Code Execution - Java Deserialization, which has been merged into an existing rule.
Cloudflare AI is deprecating several models on May 30, 2026, including Kimi K2.5, and recommends users transition to newer models with enhanced capabilities. The deprecation date for Kimi K2.5 has been extended from May 10, 2026, to May 30, 2026.
Cloudflare AI has implemented WAF protections in response to newly disclosed vulnerabilities in React and Next.js, including denial of service and other security issues. Users are strongly advised to update their applications and dependencies to the latest patched versions.
The Cloudflare One Appliance now supports custom DHCP options for LAN leases, enabling functionalities like PXE/iPXE boot and VoIP provisioning, with validation to prevent disruptions from invalid configurations.
Cloudflare One Appliance now supports breakout and traffic prioritization rules based on source, allowing users to specify source LAN interfaces or IP addresses for improved traffic management.
Cloudflare AI introduces Stream Bindings for Workers, enabling users to interact with their Stream video library directly from Workers, facilitating video uploads, management, and signed URL generation without authenticated API calls.
Cloudflare AI Workers now support automatic tracing across Worker-to-Worker subrequests, allowing for a unified trace view that includes nested spans for service bindings and Durable Objects. This enhancement facilitates better debugging and observability of cross-Worker request flows.
PhishNet users can now access AI-generated Cloudy summaries within the email investigation experience, providing key details about messages to aid in decision-making regarding suspicious emails. This feature is currently available for PhishNet with Office 365, with support for Gmail expected by the end of the quarter.
The Cloudforce One Threat Events API now supports TAXII as an output format, allowing for standardized sharing of cyber threat intelligence with security tools that utilize TAXII-formatted streams.
Cloudflare's cache has been upgraded to use the Pingora proxy, resulting in lower latency, reduced cache MISSes, and better RFC compliance, along with new features like asynchronous stale-while-revalidate and unbuffered bypass by default.
Cloudflare has introduced keyboard shortcuts for navigating and performing actions in the Cloudflare dashboard, allowing users to operate without using the mouse. Users can view the full list of shortcuts by pressing '?' and can disable them in their profile settings.
Cloudflare AI now supports the creation and management of Pipelines and R2 Data Catalog using Terraform, introducing four new resources for defining data pipelines as infrastructure-as-code.
The @cloudflare/dynamic-workflows library now allows users to run Workflows inside Dynamic Workers, enabling durable execution for runtime-loaded code and simplifying management of Workflow instances.
Cloudflare DLP now features Data Classification, allowing administrators to organize and label sensitive content with customizable labels, templates, and reusable data classes for improved content management and DLP profile consistency.
Cloudflare DLP has introduced new predefined detection entries for various credential types and sensitive information, enhancing its data loss prevention capabilities. Examples include GitHub PAT, OpenAI API Key, and Bitcoin Wallet.
The Cloudflare Go SDK v7.0.0 has been released, introducing breaking changes to three packages due to updates in the upstream API specification, including the removal of the 'SearchForAgents' metadata from instance metadata structs.
The Cloud Observatory on Radar now offers enhanced connection metrics insights, including breakdowns by cloud provider and region, as well as percentile distributions for connection times.
Cloudflare Radar now includes dark mode support, allowing users to select between light, dark, and system themes for a consistent experience across all pages and widgets.
Cloudflare AI has introduced shared dictionaries passthrough in open beta, allowing origins to compress responses using previously cached versions, improving efficiency and reducing download times significantly. This feature is now available on all plans.
This emergency release introduces a new rule to block a critical authentication bypass vulnerability in cPanel & WHM related to CVE-2026-41940, which allows unauthenticated attackers to gain administrative access. Users are advised to apply official vendor patches immediately.
Cloudflare Web Analytics now includes Navigation Type reporting and filtering, enabling users to analyze how visitors navigate between pages and the effectiveness of browser caching. This enhancement helps optimize user experience by identifying navigation patterns and potential performance bottlenecks.
Digital experience tests now support applications protected by Cloudflare Access or third-party authentication, with all authentication secrets managed via Cloudflare Secret Store. Enhanced configuration options include new HTTP methods, custom headers, and advanced settings.
The Gateway Authorization Proxy and hosted PAC files are now generally available for all plan types, providing identity-aware options for Gateway filtering without the need for a client installation. These features are particularly useful for environments where client deployment is not feasible.
Hyperdrive now supports connections to private databases through the Workers VPC service, allowing users to create configurations via the Cloudflare dashboard or command line. This feature enables secure database connections not exposed to the public Internet.
Cloudflare AI's Digital Experience Monitoring now includes dashboard notifications for Internet outages and traffic anomalies affecting Cloudflare One Client devices, utilizing data from Cloudflare Radar. Users can view detailed observations in the Radar Outage Center.
IT teams can now remotely run speed tests from the Cloudflare One Client to Cloudflare's network edge, providing metrics such as internet speed, latency, and network quality score. This feature can be accessed through the Cloudflare dashboard under the Digital experience diagnostics section.
Cloudflare DLP has introduced a new predefined profile for detecting PII records that requires at least three unique detection entries to minimize false positives. This profile includes various types of personal data such as passport numbers, credit card numbers, and email addresses.
Cloudflare AI introduces a new account-level setting called 'enforce_dns_only' that allows users to disable the reverse proxy for all zones in their account, directing DNS queries to origin IPs instead of Cloudflare's IPs. This feature is intended for incident response but comes with significant risks, including exposure of origin IPs and loss of Cloudflare protections.
Cloudflare's Queues now provide realtime backlog metrics, including backlog count, backlog bytes, and the timestamp of the oldest unacknowledged message, accessible via the dashboard and APIs. Additionally, relevant endpoints and JavaScript APIs have been updated to return these metrics.
Cache Response Rules now support zone versioning, allowing users to create and modify response-phase cache settings within a version and promote them through environments, similar to Cache Rules. This integration enhances testing and management of cache configurations across different environments.
Cloudflare now provides structured JSON and Markdown responses for 5xx error codes, aligning with RFC 9457, and includes a Retry-After header for retryable errors. This change enhances error handling by clearly indicating fault attribution and response formats.
Resource Tagging has entered public beta, allowing users to attach custom key-value metadata to Cloudflare resources and query them across their accounts. This feature includes broad resource type support, powerful filtering, and an API-first design.
The Cloudflare AI WAF release on April 27, 2026, introduces enhancements to existing rules for improved detection against web attacks, along with new rules for PostgreSQL SQL injection detection. Users are advised to monitor the Security Events dashboard for optimal security adjustments.
Cloudflare AI now generates Zero Trust Network Session Logs for all traffic proxied through Cloudflare Gateway, including previously unsupported on-ramps like proxy endpoints and Browser Isolation egress. This change may result in increased log volume for customers using these on-ramps.
Cloudflare has introduced a new CLI tool called tf-migrate to automate the migration process from Terraform Provider v4 to v5, ensuring a smoother transition with features like resource renames and attribute transformations.
Audit Logs v2 now includes support for organization-level audit logs, allowing Org Admins to retrieve audit events for actions performed at the organization level via a new API endpoint. This feature is distinct from account-level audit logs.
Custom Dashboards are now available to all Cloudflare customers, allowing personalized views of critical metrics and expanded data visualization options. Log Explorer customers can also create dashboard charts directly from log queries.
The R2 Data Catalog now automatically removes unreferenced data files during snapshot expiration, reducing storage costs and eliminating the need for manual maintenance. This enhancement allows for both metadata and data file cleanup to occur automatically when a snapshot is expired.
A new Network Overview page has been added to the Cloudflare dashboard, providing a centralized location for managing network security and connectivity products. Users can connect resources, monitor traffic, configure address maps, and explore additional services from this page.
Cloudflare AI Workflows now includes additional context properties in the step.do() callbacks, such as step name and invocation count, and supports returning ReadableStream for larger outputs.
The Container logs page now integrates related Worker and Durable Object logs, allowing users to view all relevant log events for a container application in one location. Users can also filter logs by source to isolate outputs.
Cloudflare AI introduces two new features for pay-as-you-go customers: the Billable Usage dashboard for monitoring usage-based costs and Budget alerts for setting spend thresholds with email notifications.
Cloudflare AI introduces subrequest merging for HTTP requests in Logpush, allowing subrequest data to be embedded in the parent log record instead of generating separate entries. This feature can be enabled by setting 'merge_subrequests' to true in Logpush jobs.
This release introduces a new detection for a Remote Code Execution vulnerability in Apache ActiveMQ and updates the signature for Magento 2's Unrestricted File Upload, along with ongoing rule refinements for enhanced security insights.
The Cloudflare AI WAF is introducing several new detection rules related to PostgreSQL and SQL injection, scheduled for release on April 27, 2026. These include new detections for various SQL injection patterns and will involve merging some rules with existing ones.
Binary frames received on a WebSocket are now delivered as Blob objects by default, aligning with the WebSocket specification, whereas they were previously delivered as ArrayBuffer. This change may affect existing Workers that rely on ArrayBuffer delivery for binary messages.
The new Network session analytics dashboard is now available in Cloudflare One, providing insights into network traffic patterns and key metrics such as session count and geographic distribution.
Cloudflare AI now supports sending logs directly to Pipelines for ingestion, transformation, and storage as Parquet files or Apache Iceberg tables, enhancing efficiency in log querying and storage.