Cloudflare One Updates & Release Notes
200 updates curated from 1 source by the Releasebot Team. Last updated: Sep 11, 2026
- Sep 9, 2026
- Date parsed from source:Sep 9, 2026
- First seen by Releasebot:Sep 11, 2026
Cloudflare One Client - Cloudflare One Client for macOS (version 2026.8.1290.1)
Cloudflare One adds a beta macOS client release with support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel, plus DNS and API reliability improvements and a range of fixes for diagnostics, connectivity, crashes, and client stability.
A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.
This beta release includes the following changes and improvements:
- Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
- Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
- Improved API reliability by retrying requests dropped when reusing pooled connections.
- Fixed Extra Logging failing to capture packets across all interfaces.
- Fixed an issue that could prevent remote diagnostics from completing.
- Fixed DNS connectivity checks failing on IPv6-only networks.
- Fixed the client service exiting when its route-monitoring socket was closed after sleep or wake.
- Fixed DNS enforcement checks making the client service unresponsive on systems with large routing tables.
- Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
- Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
- Fixed the client continuing to report 'No network' after a successful manual disconnect.
- Fixed a client UI crash that could occur when the daemon connection was reset during an IPC request.
- Fixed a startup crash when date formatting data for the system locale had not yet loaded.
Known issues
None
For Zero Trust documentation, see: https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/
For Consumer documentation, see: https://developers.cloudflare.com/warp-client/
Original source - Sep 9, 2026
- Date parsed from source:Sep 9, 2026
- First seen by Releasebot:Sep 11, 2026
Cloudflare One Client - Cloudflare One Client for Windows (version 2026.8.1290.1)
Cloudflare One releases a new Windows Cloudflare One Client beta with better routing, stronger DNS and API reliability, and multiple fixes for connectivity, startup, UI, TPM authentication, and device posture checks.
A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.
This beta release includes the following changes and improvements:
- Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
- Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
- Improved API reliability by retrying requests dropped when reusing pooled connections.
- The client no longer requires the Windows WLAN AutoConfig service to be running.
- Implemented a service recovery mechanism backed by Windows scheduler task to start WARP service on system unlock if not already started.
- Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
- Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
- Fixed the client continuing to report 'No network' after a successful manual disconnect.
- Fixed Digital Experience Monitoring (DEX) HTTP tests failing TLS validation on Windows.
- Fixed the client UI crashing at startup when it could not write to the Windows registry.
- Fixed latency spikes and traffic interruptions during TPM-backed API authentication when hardware-backed registration is enabled.
- Fixed trailing whitespace in BIOS serial numbers causing serial-number and client-certificate device posture checks to fail.
- Fixed a client UI crash that could occur when the daemon connection was reset during an IPC request.
- Fixed a startup crash when date formatting data for the system locale had not yet loaded.
Known issues
None
For Zero Trust documentation, see: https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/
For Consumer documentation, see: https://developers.cloudflare.com/warp-client/
Original source All of your release notes in one feed
Join Releasebot and get updates from Cloudflare and hundreds of other software products.
- Sep 9, 2026
- Date parsed from source:Sep 9, 2026
- First seen by Releasebot:Sep 11, 2026
Browser Isolation, Cloudflare One - Improved iOS tap-to-type experience for Browser Isolation
Cloudflare One improves Browser Isolation tap-to-type on iOS with a less disruptive inline prompt over focused text fields, plus a keyboard icon for smaller fields. The update applies automatically to iOS isolation sessions.
Browser Isolation has improved the tap-to-type experience for users on iOS devices.
Previously, Browser Isolation displayed a full-screen overlay with the message tap to type when users focused a text field. The prompt now appears inline over the focused text field, reducing disruption when users enter text in isolated sessions.
If the focused text field is too small to display the full prompt, Browser Isolation displays a keyboard icon in the center of the text field instead.
iOS users should tap twice to begin entering text. This update applies automatically to Browser Isolation sessions on iOS.
For more information on why this interaction is required, refer to iOS limitations.
Original source - Sep 9, 2026
- Date parsed from source:Sep 9, 2026
- First seen by Releasebot:Sep 11, 2026
CASB - New CASB integration for Zoom
Cloudflare One adds Zoom CASB integration for continuous security scanning of accounts, users, meetings, recordings, and content. It uses a pre-built OAuth app, requires no manual Zoom setup, and surfaces findings in the dashboard within minutes.
Cloudflare CASB now integrates with Zoom. The integration connects through Cloudflare's pre-built OAuth application — no manual app setup in Zoom is required. After an initial scan, CASB continuously scans your Zoom account to surface new findings as your environment changes.
Zoom is widely used for meetings, webinars, and collaboration. Misconfigurations in account settings, meeting security controls, and recording access can expose organizations to data leakage, unauthorized access, and compliance risk. Cloudflare CASB ingests Zoom account data via API to surface security findings across these areas.
Key capabilities
Starting today, security teams can scan for security findings across the following assets:
- Account settings — Detect weak password policies, unlocked security controls, and two-factor authentication gaps across your Zoom account
- User accounts — Identify users not enforcing SSO, accounts with insecure host keys, unverified or inactive users, and unsafe overrides of account-level security settings
- Meetings — Surface meetings without passwords or waiting rooms, meetings using Personal Meeting IDs (PMIs), and meetings with external domain hosts
- Recordings — Detect publicly accessible cloud recordings, recordings without passcodes, and weak recording password configurations
- Content — Identify sensitive information in meeting and recording content via DLP Profile matching
Learn more
This integration is available to all Cloudflare Zero Trust customers today. New customers can sign up and start with their first two integrations for free. Existing customers can enable the integration directly in the Cloudflare One dashboard under Cloud & SaaS findings > Integrations. The integration begins scanning immediately and surfaces findings in the dashboard within minutes.
Original source - Sep 2, 2026
- Date parsed from source:Sep 2, 2026
- First seen by Releasebot:Sep 2, 2026
Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Define custom applications for breakout and prioritized traffic from the Cloudflare One Appliance dashboard
Cloudflare One now supports creating and managing custom applications for breakout and prioritized traffic directly in the dashboard, with hostname, IP subnet, and new source subnet matching for more flexible traffic steering.
You can now define custom applications for breakout and prioritized traffic on the Cloudflare One Appliance directly from the dashboard, without calling the API.
In Traffic Steering > Breakout traffic or Prioritized traffic, select Assign application traffic > Add to create a custom application matched by Hostnames, IP subnets, and/or the new Source subnets field, alongside Cloudflare-managed applications.
Edit or delete an existing custom application from the same panel, no API round-trip required.
Source subnets lets you match traffic by its source IP range, complementing the existing source LAN interface breakout criteria.
This complements the existing API and Terraform workflow for managing applications.
For details, refer to Breakout traffic and Prioritized traffic.
Original source Similar to Cloudflare One with recent updates:
- Cloudflare AI updates152 release notes · Latest Sep 11, 2026
- Claude updates137 release notes · Latest Sep 10, 2026
- Network Security updates33 release notes · Latest Jul 8, 2026
- Claude Code updates443 release notes · Latest Sep 12, 2026
- ChatGPT updates219 release notes · Latest Sep 10, 2026
- Gemini updates414 release notes · Latest Sep 10, 2026
- Sep 2, 2026
- Date parsed from source:Sep 2, 2026
- First seen by Releasebot:Sep 2, 2026
Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Configure DHCP options from the dashboard on Cloudflare One Appliance
Cloudflare One adds custom DHCP options in the dashboard for LAN appliance setups.
You can now configure custom DHCP options directly from the dashboard when the Cloudflare One Appliance is acting as the DHCP server for a LAN.
In LAN configuration, under DHCP server options, select Add DHCP option to choose from common options for PXE / iPXE boot, VoIP phone provisioning, and vendor-specific configuration, or select Add custom option to enter your own option code, type, and value.
This complements the existing API and Terraform workflow for configuring DHCP options.
For details, refer to DHCP server options.
Original source - Sep 2, 2026
- Date parsed from source:Sep 2, 2026
- First seen by Releasebot:Sep 2, 2026
Cloudflare Tunnel, Cloudflare One, Cloudflare WAN, Cloudflare Mesh - Create multiple Cloudflare Tunnel and Cloudflare Mesh routes at once
Cloudflare One adds bulk route creation in the Routes page for Cloudflare Tunnel, Cloudflare Mesh, and WAN static routes, letting users add multiple destinations, queue routes, and retry only failed entries.
You can now create multiple Cloudflare Tunnel and Cloudflare Mesh routes from the Routes page in a single action, instead of submitting one route at a time.
When creating a route, you can now:
- Add multiple destinations at once — Enter a comma-separated list of CIDR ranges or hostnames to create several routes of the same type and connector together.
- Queue up multiple routes — Select Add another to stage additional routes, including different types or connectors, before creating them all in one action.
- Retry only what failed — If some routes in a batch fail (for example, an invalid CIDR), the routes that were created successfully are removed from the form automatically, so you only need to fix and resubmit the ones that failed.
The same Routes UI already supports bulk creation for Cloudflare WAN static routes, so you can add multiple WAN destinations or queue up several WAN routes before creating them together as well.
Go to Routes ↗
For setup steps, refer to Add routes.
Original source - Aug 28, 2026
- Date parsed from source:Aug 28, 2026
- First seen by Releasebot:Aug 28, 2026
Cloudflare One Client - Cloudflare One Client for macOS (version 2026.7.1376.0)
Cloudflare One releases a macOS client hotfix that fixes DNS query failures across platforms in the stable GA release.
A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.
This hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms.
Original source - Aug 28, 2026
- Date parsed from source:Aug 28, 2026
- First seen by Releasebot:Aug 28, 2026
Cloudflare One Client - Cloudflare One Client for Windows (version 2026.7.1376.0)
Cloudflare One adds a Windows client GA release and hotfixes rare connection and DNS query failures.
A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.
Fixed a rare but critical issue where the client could fail to connect or switch organizations due to an invalid registration after switching installed client versions. Additionally, this hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms.
Original source - Aug 28, 2026
- Date parsed from source:Aug 28, 2026
- First seen by Releasebot:Aug 28, 2026
Cloudflare One Client - Cloudflare One Client for Linux (version 2026.7.1377.0)
Cloudflare One ships a Linux client GA hotfix that fixes DNS query failures across platforms.
A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.
This hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms.
Original source - Aug 26, 2026
- Date parsed from source:Aug 26, 2026
- First seen by Releasebot:Aug 28, 2026
Access - Access service token secrets use a scannable format
Cloudflare One adds a new service token Client Secret format that improves secret scanning and keeps existing tokens working.
Cloudflare Access service token Client Secrets created on or after August 26, 2026, use the format cfast_[40 alphanumeric characters][8-character checksum]. The prefix and checksum make these credentials easier for secret scanning tools to identify with fewer false positives.
Existing service token secrets continue to work and do not require rotation. Both formats use the same Client ID and the same CF-Access-Client-Id and CF-Access-Client-Secret authentication headers.
For more information, refer to Service tokens.
Original source - Aug 25, 2026
- Date parsed from source:Aug 25, 2026
- First seen by Releasebot:Aug 26, 2026
Access - Grace periods for service token rotation
Cloudflare One adds grace periods for rotating Access service token secrets, making updates easier without interrupting authentication.
Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication.
The dashboard offers grace periods from one hour to 30 days. Administrators can also revoke the previous secret immediately. The API accepts an RFC 3339 expiration time for custom rotation schedules.
For configuration instructions, refer to Rotate service token secrets.
Original source - Aug 25, 2026
- Date parsed from source:Aug 25, 2026
- First seen by Releasebot:Aug 26, 2026
Access - Temporarily turn off Access service tokens
Cloudflare One adds temporary service token disabling in Access to help contain exposed credentials.
Cloudflare Access administrators can now temporarily turn off service tokens without deleting them. A disabled token cannot authenticate, but its configuration remains available so administrators can turn it on again later.
Turning off a token also stops any previous secret in an active rotation grace period. Use this control to contain suspected credential exposure or pause an automated service.
For configuration instructions, refer to Turn a service token on or off.
Original source - Aug 25, 2026
- Date parsed from source:Aug 25, 2026
- First seen by Releasebot:Aug 25, 2026
Cloudflare One, Access - MCP server portals support MCP 2026-07-28 specification
Cloudflare One adds stateless MCP 2026-07-28 support for server portal connections, with automatic compatibility for earlier 2025 Streamable HTTP clients and upstream servers. Client and upstream protocol selection now work independently, while SSE connections still use the legacy protocol.
MCP server portals support the stateless MCP 2026-07-28 specification for client and upstream server connections.
The portal's /mcp endpoint automatically accepts stateless MCP 2026-07-28 requests and earlier 2025 Streamable HTTP clients. When the portal connects to an upstream Streamable HTTP server, it checks for MCP 2026-07-28 support and falls back to the 2025 handshake when needed. Client and upstream protocol selection are independent, so clients and servers can upgrade separately without portal configuration changes.
SSE connections continue to use the legacy protocol. For details, refer to MCP server portal transport and protocol compatibility.
Original source - Aug 24, 2026
- Date parsed from source:Aug 24, 2026
- First seen by Releasebot:Aug 24, 2026
Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Download the Cloudflare One Virtual Appliance for your hypervisor from the dashboard
Cloudflare One adds direct Virtual Appliance downloads from the dashboard, letting users choose VMware ESXi, Proxmox, or libvirt/KVM and access setup guides without searching for asset URLs.
When you register a Cloudflare One Virtual Appliance, you can now select your hypervisor and download the appliance directly from the dashboard — no need to look up asset URLs.
On the Connectors page, select Add an appliance, choose Virtual appliance, then select your hypervisor: VMware ESXi, Proxmox, or libvirt/KVM.
Download the OVA image (VMware ESXi) or the install script (Proxmox and libvirt/KVM) for the selected hypervisor.
Use View setup guide to open deployment instructions for your platform.
This complements the existing self-serve registration and license key generation in the dashboard.
For details, refer to Configure a Cloudflare One Virtual Appliance.
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.