Application Security Updates & Release Notes
179 updates curated from 1 source by the Releasebot Team. Last updated: Oct 1, 2026
- Oct 1, 2026
- Date parsed from source:Oct 1, 2026
- First seen by Releasebot:Oct 1, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-10-01 - Emergency
Application Security adds immediate defense against a Citrix NetScaler ADC and Gateway vulnerability, introducing new blocking protection for improper input validation and arbitrary command execution risks tied to CVE-2026-88771.
This update provides immediate defense against a vulnerability affecting Citrix NetScaler ADC and Gateway appliances, deploying protection against improper input validation vectors.
Key Findings
CVE-2026-88771: An improper input validation vulnerability affecting Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to execute arbitrary commands.
Impact
We strongly recommend that administrators apply the latest versions to fully secure origin servers. Additionally, customers should review configurations against applicable preconditions and follow standard incident response processes if signs of compromise are identified.
Detailed Rule Changes
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...827ab216
N/A
Citrix Netscaler ADC and Gateway - Improper input validation - CVE:CVE-2026-88771
N/A
Block
This is a new detection.
Original source - Sep 30, 2026
- Date parsed from source:Sep 30, 2026
- First seen by Releasebot:Oct 1, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-09-30
Application Security adds new detections and stronger blocking for GitLab path traversal, HTTP request smuggling, directory traversal, and command injection attempts, expanding protection with fresh managed ruleset updates and merged beta rules.
This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.
Key Findings
CVE-2026-85706: A path traversal vulnerability affecting GitLab.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
CommentsCloudflare Managed Ruleset
...cb14ded8
N/A
Broken Access Control - Directory Traversal
Log
Block
This is a new detection.Cloudflare Managed Ruleset
...0364bd7e
N/A
HTTP Request Smuggling - Request Body Anomaly - Beta
Log
Block
This rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ...1489d892).Cloudflare Managed Ruleset
...d498a69a
N/A
Command Injection - Generic 8 - body - Beta
Disabled
Disabled
This rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ...413592e2).Cloudflare Managed Ruleset
...87ae8cfc
N/A
GitLab - Path Traversal- CVE:CVE-2026-85706
Log
Block
This is a new detection.Cloudflare Managed Ruleset
Original source
...549f7356
N/A
Generic - Request routing cache inconsistency
N/A
Block
This is a new detection. All of your release notes in one feed
Join Releasebot and get updates from Cloudflare and hundreds of other software products.
- Sep 30, 2026
- Date parsed from source:Sep 30, 2026
- First seen by Releasebot:Oct 1, 2026
Application Security by Cloudflare
WAF - WAF Release - Scheduled changes for 2026-10-06
Application Security adds new F5 BIG-IP heap-overflow detection and merges its Command Injection - Generic 8 - uri beta rule.
Announcement Date
Release Date
Release Behavior
Legacy Rule ID
Rule ID
Description
Comments
2026-09-22
2026-10-06
Log
N/A
...a056caff
Command Injection - Generic 8 - uri - Beta
This rule will be merged into the original rule "Command Injection - Generic 8 - uri" (ID: ...ee159e2e).2026-09-30
Original source
2026-10-06
Log
N/A
...7206c737
F5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127
This is a new detection. - Sep 25, 2026
- Date parsed from source:Sep 25, 2026
- First seen by Releasebot:Sep 25, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-09-25 - Emergency
Application Security adds immediate protection against critical WordPress and JFrog Artifactory vulnerabilities, including path traversal, local file inclusion, XSS, and authentication bypass attacks with new managed ruleset detections.
This update provides immediate defense against critical vulnerabilities affecting WordPress and JFrog Artifactory, including path traversal, local file inclusion (LFI), cross-site scripting (XSS), and authentication bypass exploits.
Key Findings
CVE-2026-87902: A high-severity Path Traversal and Local File Inclusion (LFI) vulnerability affecting WordPress. Unauthenticated attackers can exploit this flaw to read arbitrary files on the host server, potentially exposing sensitive configuration data or system files.
CVE-2026-42018 & CVE-2026-82329: Critical authentication bypass vulnerabilities affecting JFrog Artifactory. Successful exploitation allows unauthenticated attackers to bypass security controls and achieve unauthorized access to the Artifactory instance.
Impact
We strongly recommend that administrators apply the latest vendor patches for WordPress and JFrog Artifactory to fully secure origin servers.
Detailed Rule Changes
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...70a43f96
N/A
Wordpress - Path Traversal, Local File Inclusion - CVE:CVE-2026-87902
N/A
Block
This is a new detection.
Cloudflare Managed Ruleset
...909a4db4
N/A
Wordpress - XSS - Comment
N/A
Block
This is a new detection.
Cloudflare Managed Ruleset
...c797ef03
N/A
JFrog Artifactory - Authentication Bypass - CVE:CVE-2026-42018
N/A
Block
This is a new detection.
Cloudflare Managed Ruleset
...a813ac74
N/A
JFrog Artifactory - Authentication Bypass - CVE:CVE-2026-82329
N/A
Block
This is a new detection.
Original source - Sep 22, 2026
- Date parsed from source:Sep 22, 2026
- First seen by Releasebot:Sep 23, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-09-22
Application Security adds new threat detections to block SSRF attacks using non-standard IP notations and jar loopback payloads, plus new SSTI defenses for Jinja environments.
This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
CommentsCloudflare Managed Ruleset
...5f21b651
N/A
SSRF - Cloud,Link-Local non-standard IP notation
Log
Block
This is a new detection.Cloudflare Managed Ruleset
...0f0313d6
N/A
SSRF - Block jar HTTP loopback payload
Log
Block
This is a new detection.Cloudflare Managed Ruleset
...75cd912a
N/A
SSRF - Local non-standard IP notation
Log
Block
This is a new detection.Cloudflare Managed Ruleset
Original source
...a1ba83f6
N/A
SSTI - Jinja Dangerous Globals Chain
Log
Block
This is a new detection. Similar to Application Security with recent updates:
- Network Security updates35 release notes ยท Latest Sep 25, 2026
- Analytics updates136 release notes ยท Latest Oct 2, 2026
- Cloudflare AI updates169 release notes ยท Latest Oct 2, 2026
- ChatGPT updates230 release notes ยท Latest Oct 2, 2026
- Claude updates151 release notes ยท Latest Oct 1, 2026
- OpenAI updates236 release notes ยท Latest Oct 1, 2026
- Sep 22, 2026
- Date parsed from source:Sep 22, 2026
- First seen by Releasebot:Sep 23, 2026
Application Security by Cloudflare
WAF - WAF Release - Scheduled changes for 2026-09-29
Application Security adds new detections for directory traversal, GitLab path traversal CVE-2026-85706, and HTTP request smuggling and command injection beta rules that will be merged into existing signatures.
Announcement Date
Release Date
Release Behavior
Legacy Rule ID
Rule ID
Description
Comments
2026-09-22
2026-09-29
Log
N/A
...cb14ded8
Broken Access Control - Directory Traversal
This is a new detection.2026-09-22
2026-09-29
Log
N/A
...0364bd7e
HTTP Request Smuggling - Request Body Anomaly - Beta
This rule will be merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ...1489d892).2026-09-22
2026-09-29
Disabled
N/A
...d498a69a
Command Injection - Generic 8 - body - Beta
This rule will be merged into the original rule "Command Injection - Generic 8 - body" (ID: ...413592e2).2026-09-22
2026-09-29
Log
N/A
...a056caff
Command Injection - Generic 8 - uri - Beta
This rule will be merged into the original rule "Command Injection - Generic 8 - uri" (ID: ...ee159e2e).2026-09-22
Original source
2026-09-29
Log
N/A
...87ae8cfc
GitLab - Path Traversal- CVE:CVE-2026-85706
This is a new detection. - Sep 16, 2026
- Date parsed from source:Sep 16, 2026
- First seen by Releasebot:Sep 30, 2026
Application Security by Cloudflare
Bots - Control JavaScript Detections API results
Application Security adds control for using JavaScript Detections API results in Enterprise Bot Management, letting customers turn API traffic scoring on or off in Security settings or through the Bot Management API.
Enterprise Bot Management customers can control whether Cloudflare uses results created through the JavaScript Detections API for bot scoring and detections.
Turn JavaScript Detections for API traffic on or off in Security > Settings. You can also configure the zone through the Bot Management API by setting
jsd_api_results_enabled:{ "jsd_api_results_enabled": true }This setting is separate from zone-wide script injection. When it is off, the API script can still execute and return success to the callback, but Cloudflare does not consume the result.
For more information, refer to JavaScript Detections.
Original source - Sep 15, 2026
- Date parsed from source:Sep 15, 2026
- First seen by Releasebot:Sep 15, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-09-15
Application Security adds new threat detections to block command injection, cloud metadata SSRF, and version control information disclosure, strengthening protection with updated managed ruleset coverage.
This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...ca453d31
N/A
SSRF - Cloud - 3
Log
Block
This is a new detection.
Cloudflare Managed Ruleset
...e540f17f
N/A
Version Control - Information Disclosure - Beta
Log
Block
This rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529).
Cloudflare Managed Ruleset
...ba458b4b
N/A
Command Injection - Generic 10
Log
Block
This is a new detection.
Original source - Sep 15, 2026
- Date parsed from source:Sep 15, 2026
- First seen by Releasebot:Sep 15, 2026
Application Security by Cloudflare
WAF - WAF Release - Scheduled changes for 2026-09-22
Application Security adds new SSRF and SSTI detections for loopback payloads, non-standard IP notation, and dangerous Jinja globals.
Announcement Date
Release Date
Release Behavior
Legacy Rule ID
Rule ID
Description
Comments
2026-09-15
2026-09-22
Log
N/A
...0f0313d6
SSRF - Block jar HTTP loopback payload
This is a new detection.
2026-09-15
2026-09-22
Log
N/A
...5f21b651
SSRF - Cloud,Link-Local non-standard IP notation
This is a new detection.
2026-09-15
2026-09-22
Log
N/A
...75cd912a
SSRF - Local non-standard IP notation
This is a new detection.
2026-09-15
2026-09-22
Log
N/A
...a1ba83f6
SSTI - Jinja Dangerous Globals Chain
This is a new detection.
Original source - Sep 10, 2026
- Date parsed from source:Sep 10, 2026
- First seen by Releasebot:Sep 10, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-09-10 - Emergency
Application Security adds an emergency managed rule for Adobe Commerce and Magento Open Source, delivering immediate edge-level mitigation and virtual patching for an actively exploited zero-day RCE. The update blocks the attack and introduces a new detection for CVE-2026-75650.
This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts.
Key Findings
Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmuggler"): Unauthenticated Remote Code Execution (RCE) vulnerability caused by improper neutralization of special elements in the platform's template engine. Unauthenticated attackers can inject arbitrary PHP payloads through style properties to execute system commands and deploy persistent malware.
Impact
This emergency rule provides immediate edge-level mitigation and virtual patching, origin applications must be urgently updated. We strongly recommend to apply the hotfix outlined in Adobe Security Bulletin APSB26-146 and immediately rotate all potentially exposed encryption keys, integration tokens, and system credentials, as patching alone does not remediate an existing compromise.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...440f5c55
N/A
Adobe Commerce - Remote Code Execution - CVE:CVE-2026-75650
N/A
Block
This is a new detection.
Original source - Sep 8, 2026
- Date parsed from source:Sep 8, 2026
- First seen by Releasebot:Sep 8, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-09-08
Application Security improves detection for Next.js remote code execution vulnerabilities by merging active beta rules into baseline signatures, strengthening coverage for image optimizer and CVE-2026-75604 protections.
This release enhances detection logic for existing rules targeting Next.js remote code execution (RCE) vulnerabilities by consolidating active beta rules into baseline signatures.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...c76ba662
N/A
Next.js - Image Optimizer Remote Code Execution via Crafted AVIF - Beta
Log
Block
This rule is merged into the original rule "Next.js - Image Optimizer Remote Code Execution via Crafted AVIF" (ID: ...80256efe).
Cloudflare Managed Ruleset
...208457cf
N/A
Next.js - Remote Code Execution - CVE:CVE-2026-75604 - Beta
Log
Block
This rule is merged into the original rule "Next.js - Remote Code Execution - CVE:CVE-2026-75604" (ID: ...2ca6cce3).
Original source - Sep 8, 2026
- Date parsed from source:Sep 8, 2026
- First seen by Releasebot:Sep 8, 2026
- Modified by Releasebot:Sep 10, 2026
Application Security by Cloudflare
WAF - WAF Release - Scheduled changes for 2026-09-15
Application Security adds new SSRF cloud and command injection detections plus a beta version control information disclosure rule.
Announcement Date
Release Date
Release Behavior
Legacy Rule ID
Rule ID
Description
Comments
2026-09-08
2026-09-15
Log
N/A
...ca453d31
SSRF - Cloud - 3
This is a new detection.2026-09-08
2026-09-15
Log
N/A
...e540f17f
Version Control - Information Disclosure - Beta
This rule will be merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529).2026-09-08
Original source
2026-09-15
Log
N/A
...ba458b4b
Command Injection - Generic 10
This is a new detection. - Sep 7, 2026
- Date parsed from source:Sep 7, 2026
- First seen by Releasebot:Oct 2, 2026
Application Security by Cloudflare
WAF - Attack Signature Detection is now available in Early Access
Application Security adds Attack Signature Detection in Early Access, letting users review Cloudflare attack signature matches in Security Analytics before choosing a mitigation response and use those signals in Security Rules for scoped protection.
Attack Signature Detection is now available in Early Access. It evaluates requests against Cloudflare attack signatures and records matches without applying a mitigation action, allowing you to investigate detected traffic before deciding how to respond.
In Security Analytics > Attack Analysis, you can review matching signature references, categories, confidence levels, and request outcomes. You can then use these fields in Security Rules and combine them with request properties such as hostname, path, and HTTP method to apply scoped mitigation.
Attack Signature Detection uses the same signature definitions as Cloudflare Managed Rules, but it does not inherit your Managed Rules actions, overrides, or deployment configuration. Managed Rules remain the recommended baseline protection during Early Access.
Contact your Cloudflare account team to request access. For more information, refer to Attack Signature Detection.
Original source - Sep 7, 2026
- Date parsed from source:Sep 7, 2026
- First seen by Releasebot:Sep 20, 2026
Application Security by Cloudflare
WAF - Enforce positive security with Application Profiles
Application Security adds Application Profiles to Cloudflare WAF, learning valid request shapes with Schema Profiles and always-on conformance detection. It also adds Profile Analysis for trends and Custom Rule enforcement, with a closed beta for invited Enterprise customers.
Application Profiles add a positive-security layer to Cloudflare WAF. Instead of looking only for requests that resemble known attacks, Application Profiles learn what valid requests to your application look like and identify traffic that deviates from the expected structure.
The first available profile type, Schema Profiles, can learn path variables, query parameters, headers, cookies, JSON bodies, and form-encoded bodies. Profiles model field types and constraints such as numeric ranges, string lengths, and character classes. After a profile becomes available, an always-on detection classifies requests as conforming or non-conforming without blocking traffic.
Use Profile Analysis in Security Analytics to review conformance trends and sampled violation details before enforcing a profile. When you are ready to mitigate traffic, use a Custom Rule to scope enforcement by hostname, path, operation, or other security signals such as Attack Score.
Customers with API Security already have access to Schema Profiles through Schema Learning and Schema Validation. Cloudflare is also opening a closed beta to invited Enterprise customers without API Security. Contact your Cloudflare account team to express interest.
For more information, refer to Application Profiles.
Original source - Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 2, 2026
Application Security by Cloudflare
WAF - WAF Release - 2026-09-01
Application Security adds new SQL injection detection for WHERE comparisons with WITH clauses, improving protection against complex queries.
This release introduces a new threat detection to enhance protection against SQL injection (SQLi) attempts exploiting complex query syntax.
Key Findings
- SQLi Protection: Improved coverage for SQL injection patterns involving WHERE comparisons combined with WITH clauses.
Ruleset
- Rule ID
- Legacy Rule ID
- Description
- Previous Action
- New Action
- Comments
- Cloudflare Managed Ruleset
- ...bcfa0966
- N/A
- SQLi - WHERE Comparison With WITH Clause
- Log
- Block
- This is a new detection.
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.