Application Security Updates & Release Notes

Follow

179 updates curated from 1 source by the Releasebot Team. Last updated: Oct 1, 2026

Get this feed:
  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-10-01 - Emergency

    Application Security adds immediate defense against a Citrix NetScaler ADC and Gateway vulnerability, introducing new blocking protection for improper input validation and arbitrary command execution risks tied to CVE-2026-88771.

    This update provides immediate defense against a vulnerability affecting Citrix NetScaler ADC and Gateway appliances, deploying protection against improper input validation vectors.

    Key Findings

    CVE-2026-88771: An improper input validation vulnerability affecting Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to execute arbitrary commands.

    Impact

    We strongly recommend that administrators apply the latest versions to fully secure origin servers. Additionally, customers should review configurations against applicable preconditions and follow standard incident response processes if signs of compromise are identified.

    Detailed Rule Changes

    Ruleset

    Rule ID

    Legacy Rule ID

    Description

    Previous Action

    New Action

    Comments

    Cloudflare Managed Ruleset

    ...827ab216

    N/A

    Citrix Netscaler ADC and Gateway - Improper input validation - CVE:CVE-2026-88771

    N/A

    Block

    This is a new detection.

    Original source
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-09-30

    Application Security adds new detections and stronger blocking for GitLab path traversal, HTTP request smuggling, directory traversal, and command injection attempts, expanding protection with fresh managed ruleset updates and merged beta rules.

    This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.

    Key Findings

    CVE-2026-85706: A path traversal vulnerability affecting GitLab.

    Ruleset

    Rule ID
    Legacy Rule ID
    Description
    Previous Action
    New Action
    Comments

    Cloudflare Managed Ruleset
    ...cb14ded8
    N/A
    Broken Access Control - Directory Traversal
    Log
    Block
    This is a new detection.

    Cloudflare Managed Ruleset
    ...0364bd7e
    N/A
    HTTP Request Smuggling - Request Body Anomaly - Beta
    Log
    Block
    This rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ...1489d892).

    Cloudflare Managed Ruleset
    ...d498a69a
    N/A
    Command Injection - Generic 8 - body - Beta
    Disabled
    Disabled
    This rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ...413592e2).

    Cloudflare Managed Ruleset
    ...87ae8cfc
    N/A
    GitLab - Path Traversal- CVE:CVE-2026-85706
    Log
    Block
    This is a new detection.

    Cloudflare Managed Ruleset
    ...549f7356
    N/A
    Generic - Request routing cache inconsistency
    N/A
    Block
    This is a new detection.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Cloudflare and hundreds of other software products.

    Create account
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - Scheduled changes for 2026-10-06

    Application Security adds new F5 BIG-IP heap-overflow detection and merges its Command Injection - Generic 8 - uri beta rule.

    Announcement Date

    Release Date

    Release Behavior

    Legacy Rule ID

    Rule ID

    Description

    Comments

    2026-09-22
    2026-10-06
    Log
    N/A
    ...a056caff
    Command Injection - Generic 8 - uri - Beta
    This rule will be merged into the original rule "Command Injection - Generic 8 - uri" (ID: ...ee159e2e).

    2026-09-30
    2026-10-06
    Log
    N/A
    ...7206c737
    F5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127
    This is a new detection.

    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 25, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-09-25 - Emergency

    Application Security adds immediate protection against critical WordPress and JFrog Artifactory vulnerabilities, including path traversal, local file inclusion, XSS, and authentication bypass attacks with new managed ruleset detections.

    This update provides immediate defense against critical vulnerabilities affecting WordPress and JFrog Artifactory, including path traversal, local file inclusion (LFI), cross-site scripting (XSS), and authentication bypass exploits.

    Key Findings

    CVE-2026-87902: A high-severity Path Traversal and Local File Inclusion (LFI) vulnerability affecting WordPress. Unauthenticated attackers can exploit this flaw to read arbitrary files on the host server, potentially exposing sensitive configuration data or system files.

    CVE-2026-42018 & CVE-2026-82329: Critical authentication bypass vulnerabilities affecting JFrog Artifactory. Successful exploitation allows unauthenticated attackers to bypass security controls and achieve unauthorized access to the Artifactory instance.

    Impact

    We strongly recommend that administrators apply the latest vendor patches for WordPress and JFrog Artifactory to fully secure origin servers.

    Detailed Rule Changes

    Ruleset

    Rule ID

    Legacy Rule ID

    Description

    Previous Action

    New Action

    Comments

    Cloudflare Managed Ruleset

    ...70a43f96

    N/A

    Wordpress - Path Traversal, Local File Inclusion - CVE:CVE-2026-87902

    N/A

    Block

    This is a new detection.

    Cloudflare Managed Ruleset

    ...909a4db4

    N/A

    Wordpress - XSS - Comment

    N/A

    Block

    This is a new detection.

    Cloudflare Managed Ruleset

    ...c797ef03

    N/A

    JFrog Artifactory - Authentication Bypass - CVE:CVE-2026-42018

    N/A

    Block

    This is a new detection.

    Cloudflare Managed Ruleset

    ...a813ac74

    N/A

    JFrog Artifactory - Authentication Bypass - CVE:CVE-2026-82329

    N/A

    Block

    This is a new detection.

    Original source
  • Sep 22, 2026
    • Date parsed from source:
      Sep 22, 2026
    • First seen by Releasebot:
      Sep 23, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-09-22

    Application Security adds new threat detections to block SSRF attacks using non-standard IP notations and jar loopback payloads, plus new SSTI defenses for Jinja environments.

    This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.

    Ruleset

    Rule ID
    Legacy Rule ID
    Description
    Previous Action
    New Action
    Comments

    Cloudflare Managed Ruleset
    ...5f21b651
    N/A
    SSRF - Cloud,Link-Local non-standard IP notation
    Log
    Block
    This is a new detection.

    Cloudflare Managed Ruleset
    ...0f0313d6
    N/A
    SSRF - Block jar HTTP loopback payload
    Log
    Block
    This is a new detection.

    Cloudflare Managed Ruleset
    ...75cd912a
    N/A
    SSRF - Local non-standard IP notation
    Log
    Block
    This is a new detection.

    Cloudflare Managed Ruleset
    ...a1ba83f6
    N/A
    SSTI - Jinja Dangerous Globals Chain
    Log
    Block
    This is a new detection.

    Original source
  • Similar to Application Security with recent updates:

  • Sep 22, 2026
    • Date parsed from source:
      Sep 22, 2026
    • First seen by Releasebot:
      Sep 23, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - Scheduled changes for 2026-09-29

    Application Security adds new detections for directory traversal, GitLab path traversal CVE-2026-85706, and HTTP request smuggling and command injection beta rules that will be merged into existing signatures.

    Announcement Date

    Release Date

    Release Behavior

    Legacy Rule ID

    Rule ID

    Description

    Comments

    2026-09-22
    2026-09-29
    Log
    N/A
    ...cb14ded8
    Broken Access Control - Directory Traversal
    This is a new detection.

    2026-09-22
    2026-09-29
    Log
    N/A
    ...0364bd7e
    HTTP Request Smuggling - Request Body Anomaly - Beta
    This rule will be merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ...1489d892).

    2026-09-22
    2026-09-29
    Disabled
    N/A
    ...d498a69a
    Command Injection - Generic 8 - body - Beta
    This rule will be merged into the original rule "Command Injection - Generic 8 - body" (ID: ...413592e2).

    2026-09-22
    2026-09-29
    Log
    N/A
    ...a056caff
    Command Injection - Generic 8 - uri - Beta
    This rule will be merged into the original rule "Command Injection - Generic 8 - uri" (ID: ...ee159e2e).

    2026-09-22
    2026-09-29
    Log
    N/A
    ...87ae8cfc
    GitLab - Path Traversal- CVE:CVE-2026-85706
    This is a new detection.

    Original source
  • Sep 16, 2026
    • Date parsed from source:
      Sep 16, 2026
    • First seen by Releasebot:
      Sep 30, 2026
    Cloudflare logo

    Application Security by Cloudflare

    Bots - Control JavaScript Detections API results

    Application Security adds control for using JavaScript Detections API results in Enterprise Bot Management, letting customers turn API traffic scoring on or off in Security settings or through the Bot Management API.

    Enterprise Bot Management customers can control whether Cloudflare uses results created through the JavaScript Detections API for bot scoring and detections.

    Turn JavaScript Detections for API traffic on or off in Security > Settings. You can also configure the zone through the Bot Management API by setting jsd_api_results_enabled:

    {
      "jsd_api_results_enabled": true
    }
    

    This setting is separate from zone-wide script injection. When it is off, the API script can still execute and return success to the callback, but Cloudflare does not consume the result.

    For more information, refer to JavaScript Detections.

    Original source
  • Sep 15, 2026
    • Date parsed from source:
      Sep 15, 2026
    • First seen by Releasebot:
      Sep 15, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-09-15

    Application Security adds new threat detections to block command injection, cloud metadata SSRF, and version control information disclosure, strengthening protection with updated managed ruleset coverage.

    This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history.

    Ruleset

    Rule ID

    Legacy Rule ID

    Description

    Previous Action

    New Action

    Comments

    Cloudflare Managed Ruleset

    ...ca453d31

    N/A

    SSRF - Cloud - 3

    Log

    Block

    This is a new detection.

    Cloudflare Managed Ruleset

    ...e540f17f

    N/A

    Version Control - Information Disclosure - Beta

    Log

    Block

    This rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529).

    Cloudflare Managed Ruleset

    ...ba458b4b

    N/A

    Command Injection - Generic 10

    Log

    Block

    This is a new detection.

    Original source
  • Sep 15, 2026
    • Date parsed from source:
      Sep 15, 2026
    • First seen by Releasebot:
      Sep 15, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - Scheduled changes for 2026-09-22

    Application Security adds new SSRF and SSTI detections for loopback payloads, non-standard IP notation, and dangerous Jinja globals.

    Announcement Date

    Release Date

    Release Behavior

    Legacy Rule ID

    Rule ID

    Description

    Comments

    2026-09-15

    2026-09-22

    Log

    N/A

    ...0f0313d6

    SSRF - Block jar HTTP loopback payload

    This is a new detection.

    2026-09-15

    2026-09-22

    Log

    N/A

    ...5f21b651

    SSRF - Cloud,Link-Local non-standard IP notation

    This is a new detection.

    2026-09-15

    2026-09-22

    Log

    N/A

    ...75cd912a

    SSRF - Local non-standard IP notation

    This is a new detection.

    2026-09-15

    2026-09-22

    Log

    N/A

    ...a1ba83f6

    SSTI - Jinja Dangerous Globals Chain

    This is a new detection.

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-09-10 - Emergency

    Application Security adds an emergency managed rule for Adobe Commerce and Magento Open Source, delivering immediate edge-level mitigation and virtual patching for an actively exploited zero-day RCE. The update blocks the attack and introduces a new detection for CVE-2026-75650.

    This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts.

    Key Findings

    Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmuggler"): Unauthenticated Remote Code Execution (RCE) vulnerability caused by improper neutralization of special elements in the platform's template engine. Unauthenticated attackers can inject arbitrary PHP payloads through style properties to execute system commands and deploy persistent malware.

    Impact

    This emergency rule provides immediate edge-level mitigation and virtual patching, origin applications must be urgently updated. We strongly recommend to apply the hotfix outlined in Adobe Security Bulletin APSB26-146 and immediately rotate all potentially exposed encryption keys, integration tokens, and system credentials, as patching alone does not remediate an existing compromise.

    Ruleset

    Rule ID

    Legacy Rule ID

    Description

    Previous Action

    New Action

    Comments

    Cloudflare Managed Ruleset

    ...440f5c55

    N/A

    Adobe Commerce - Remote Code Execution - CVE:CVE-2026-75650

    N/A

    Block

    This is a new detection.

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 8, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-09-08

    Application Security improves detection for Next.js remote code execution vulnerabilities by merging active beta rules into baseline signatures, strengthening coverage for image optimizer and CVE-2026-75604 protections.

    This release enhances detection logic for existing rules targeting Next.js remote code execution (RCE) vulnerabilities by consolidating active beta rules into baseline signatures.

    Ruleset

    Rule ID

    Legacy Rule ID

    Description

    Previous Action

    New Action

    Comments

    Cloudflare Managed Ruleset

    ...c76ba662

    N/A

    Next.js - Image Optimizer Remote Code Execution via Crafted AVIF - Beta

    Log

    Block

    This rule is merged into the original rule "Next.js - Image Optimizer Remote Code Execution via Crafted AVIF" (ID: ...80256efe).

    Cloudflare Managed Ruleset

    ...208457cf

    N/A

    Next.js - Remote Code Execution - CVE:CVE-2026-75604 - Beta

    Log

    Block

    This rule is merged into the original rule "Next.js - Remote Code Execution - CVE:CVE-2026-75604" (ID: ...2ca6cce3).

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 8, 2026
    • Modified by Releasebot:
      Sep 10, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - Scheduled changes for 2026-09-15

    Application Security adds new SSRF cloud and command injection detections plus a beta version control information disclosure rule.

    Announcement Date

    Release Date

    Release Behavior

    Legacy Rule ID

    Rule ID

    Description

    Comments

    2026-09-08
    2026-09-15
    Log
    N/A
    ...ca453d31
    SSRF - Cloud - 3
    This is a new detection.

    2026-09-08
    2026-09-15
    Log
    N/A
    ...e540f17f
    Version Control - Information Disclosure - Beta
    This rule will be merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529).

    2026-09-08
    2026-09-15
    Log
    N/A
    ...ba458b4b
    Command Injection - Generic 10
    This is a new detection.

    Original source
  • Sep 7, 2026
    • Date parsed from source:
      Sep 7, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - Attack Signature Detection is now available in Early Access

    Application Security adds Attack Signature Detection in Early Access, letting users review Cloudflare attack signature matches in Security Analytics before choosing a mitigation response and use those signals in Security Rules for scoped protection.

    Attack Signature Detection is now available in Early Access. It evaluates requests against Cloudflare attack signatures and records matches without applying a mitigation action, allowing you to investigate detected traffic before deciding how to respond.

    In Security Analytics > Attack Analysis, you can review matching signature references, categories, confidence levels, and request outcomes. You can then use these fields in Security Rules and combine them with request properties such as hostname, path, and HTTP method to apply scoped mitigation.

    Attack Signature Detection uses the same signature definitions as Cloudflare Managed Rules, but it does not inherit your Managed Rules actions, overrides, or deployment configuration. Managed Rules remain the recommended baseline protection during Early Access.

    Contact your Cloudflare account team to request access. For more information, refer to Attack Signature Detection.

    Original source
  • Sep 7, 2026
    • Date parsed from source:
      Sep 7, 2026
    • First seen by Releasebot:
      Sep 20, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - Enforce positive security with Application Profiles

    Application Security adds Application Profiles to Cloudflare WAF, learning valid request shapes with Schema Profiles and always-on conformance detection. It also adds Profile Analysis for trends and Custom Rule enforcement, with a closed beta for invited Enterprise customers.

    Application Profiles add a positive-security layer to Cloudflare WAF. Instead of looking only for requests that resemble known attacks, Application Profiles learn what valid requests to your application look like and identify traffic that deviates from the expected structure.

    The first available profile type, Schema Profiles, can learn path variables, query parameters, headers, cookies, JSON bodies, and form-encoded bodies. Profiles model field types and constraints such as numeric ranges, string lengths, and character classes. After a profile becomes available, an always-on detection classifies requests as conforming or non-conforming without blocking traffic.

    Use Profile Analysis in Security Analytics to review conformance trends and sampled violation details before enforcing a profile. When you are ready to mitigate traffic, use a Custom Rule to scope enforcement by hostname, path, operation, or other security signals such as Attack Score.

    Customers with API Security already have access to Schema Profiles through Schema Learning and Schema Validation. Cloudflare is also opening a closed beta to invited Enterprise customers without API Security. Contact your Cloudflare account team to express interest.

    For more information, refer to Application Profiles.

    Original source
  • Sep 1, 2026
    • Date parsed from source:
      Sep 1, 2026
    • First seen by Releasebot:
      Sep 2, 2026
    Cloudflare logo

    Application Security by Cloudflare

    WAF - WAF Release - 2026-09-01

    Application Security adds new SQL injection detection for WHERE comparisons with WITH clauses, improving protection against complex queries.

    This release introduces a new threat detection to enhance protection against SQL injection (SQLi) attempts exploiting complex query syntax.

    Key Findings

    • SQLi Protection: Improved coverage for SQL injection patterns involving WHERE comparisons combined with WITH clauses.

    Ruleset

    • Rule ID
    • Legacy Rule ID
    • Description
    • Previous Action
    • New Action
    • Comments
    • Cloudflare Managed Ruleset
    • ...bcfa0966
    • N/A
    • SQLi - WHERE Comparison With WITH Clause
    • Log
    • Block
    • This is a new detection.
    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.