Cloudflare One Updates & Release Notes
216 updates curated from 1 source by the Releasebot Team. Last updated: Oct 3, 2026
- Oct 2, 2026
- Date parsed from source:Oct 2, 2026
- First seen by Releasebot:Oct 3, 2026
Access, Cloudflare One - New strict service token authentication setting for Access
Cloudflare One adds strict service token authentication for Zero Trust Access, making service token requests consistently return 401 or 403 on failure, ignore Allow policies and CF_Authorization cookies, and use service token headers for access. New orgs get it on by default.
The strict service token authentication setting applies consistent behavior to requests made with service tokens. When the setting is on for a Zero Trust organization, Access handles requests with service token headers as follows:
- If authentication or authorization fails, Access always returns 401 or 403 instead of redirecting the client to the login page with 302.
- Only Service Auth policies can authorize the request. Access ignores Allow policies and any CF_Authorization cookie sent with the request.
- Access does not return a CF_Authorization cookie to the client after successful authentication. Subsequent requests should continue to use service token headers.
- Failed requests for recognized service tokens appear in Access authentication logs.
- Zero Trust organizations created on or after October 5, 2026 have strict service token authentication turned on by default and cannot turn it off. Cloudflare recommends that existing organizations turn it on as well.
- Organizations created before October 5, 2026 can configure the setting in the dashboard or through the API.
In the Cloudflare dashboard ↗︎, go to Zero Trust > Access controls > Access settings.
Go to Access settings ↗
Under Manage service tokens, turn on Strict service token authentication.
In the confirmation dialog, select Enable.
To turn off strict service token authentication, turn off the setting and select Disable.
curl "https://api.cloudflare.com/client/v4/accounts/%7Baccount_id%7D/access/organizations" \ --request PATCH \ --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \ --json '{ "strict_service_token_auth": true }'To turn off strict service token authentication, set strict_service_token_auth to false.
For behavior and configuration details, refer to Strict service token authentication.
Original source - Oct 1, 2026
- Date parsed from source:Oct 1, 2026
- First seen by Releasebot:Oct 2, 2026
Cloudflare One, Access - Simplified permissions for tagging targets with Access for Infrastructure
Cloudflare One now lets you tag targets with only the Zero Trust Write API token permission, simplifying Infrastructure Access target tagging.
You can now tag targets using only the Zero Trust Write API token permission. Previously, tagging targets through the API required both Zero Trust Write and Tag Write permissions on the API token.
This change applies to inline target tagging through the Infrastructure Access Targets API. Tagging resources through the general Resource Tagging API still requires the Tag Admin, Tag Write, or equivalent role.
For more information, refer to Tag targets.
Original source All of your release notes in one feed
Join Releasebot and get updates from Cloudflare and hundreds of other software products.
- Sep 30, 2026
- Date parsed from source:Sep 30, 2026
- First seen by Releasebot:Oct 1, 2026
Browser Isolation, Gateway, Cloudflare One - Role-based access control for Browser Isolation policies
Cloudflare One adds RBAC support for isolation policies in Gateway, letting account-level and resource-scoped roles control who can manage HTTP isolation policies and their related copy/paste, download, upload, keyboard, and printing settings.
Isolation policies support role-based access control (RBAC). Because isolation policies are Gateway HTTP policies with the Isolate action, Gateway's account-level and resource-scoped roles apply to them directly.
Use the Zero Trust HTTP Policies Admin account-level role to grant access to all HTTP policies in the account. You can also assign a resource-scoped role to let a team member manage a specific isolation policy without exposing other Gateway resources.
Policy settings such as copy/paste, file download/upload, keyboard, and printing are part of the policy object and follow the same permissions.
For setup instructions, refer to Granular permissions for Gateway.
Original source - Sep 30, 2026
- Date parsed from source:Sep 30, 2026
- First seen by Releasebot:Sep 11, 2026
- Modified by Releasebot:Oct 3, 2026
Cloudflare One Client - Cloudflare One Client for Windows (version 2026.8.2033.1)
Cloudflare One releases a Windows Cloudflare One Client beta with stronger connection reliability, improved DNS and API behavior, added non-RFC 1918 local IPv4 routing support, and multiple fixes for startup, reconnect, UI, posture, and tunnel issues.
A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.
This beta release includes the following changes and improvements:
- Fixed an issue that could briefly block traffic to split tunnel excluded resources while the client was connecting or reconnecting.
- Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
- Improved client reaction to the current network lowering its MTU.
- Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
- Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
- Improved API reliability by retrying requests dropped when reusing pooled connections.
- The client no longer requires the Windows WLAN AutoConfig service to be running.
- Implemented a service recovery mechanism backed by Windows scheduler task to start WARP service on system unlock if not already started.
- Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
- Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
- Fixed the client continuing to report 'No network' after a successful manual disconnect.
- Fixed Digital Experience Monitoring (DEX) HTTP tests failing TLS validation on Windows.
- Fixed the client UI crashing at startup when it could not write to the Windows registry.
- Fixed latency spikes and traffic interruptions during TPM-backed API authentication when hardware-backed registration is enabled.
- Fixed trailing whitespace in BIOS serial numbers causing serial-number and client-certificate device posture checks to fail.
- Fixed a client UI crash that could occur when the daemon connection was reset during an IPC request.
- Fixed a startup crash when date formatting data for the system locale had not yet loaded.
Known issues
None
For Zero Trust documentation, see: https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/
For Consumer documentation, see: https://developers.cloudflare.com/warp-client/
Original source - Sep 29, 2026
- Date parsed from source:Sep 29, 2026
- First seen by Releasebot:Sep 29, 2026
Cloudflare Mesh, Cloudflare Tunnel, Cloudflare One, Gateway, Workers VPC - Identify Mesh, Workers VPC, and Cloudflare Tunnel replicas in network logs
Cloudflare One adds clearer network session logging for Mesh and Workers VPC traffic, helping teams distinguish laptops, Mesh nodes and AI agents on Workers while tracing sessions to the exact Tunnel and cloudflared replica that handled them.
You can now tell a person on a laptop apart from a Mesh node or an AI agent running on Workers, without matching on connector email addresses or Mesh IP ranges — and see exactly which Cloudflare Tunnel and cloudflared replica received each session.
Gateway network logs and Zero Trust Network Session Logs now identify two new kinds of traffic:
- Mesh — Traffic sent from or delivered to a Cloudflare Mesh node. Previously, Mesh nodes were logged the same way as devices running the Cloudflare One Client, because Mesh nodes run the client in headless mode.
- Workers VPC — Traffic sent by a Worker through a Workers VPC binding. Previously, Workers VPC sessions were not recorded in Network Session Logs.
Gateway network logs
To view these values in the dashboard, go to Zero Trust > Insights & Logs > Logs > Network logs, select Columns, and turn on Traffic Source and Traffic Destination. Both values also appear under Network query details when you open a log entry.
Network Session Logs
The zero_trust_network_sessions dataset, available through Logpush, includes the following fields:
Field Description OnrampType How the session entered Cloudflare One. Values: CF1_CLIENT, MESH, WORKERS_VPC, MAGIC, OTHER. Offramp Where the session was routed. Sessions routed to a Mesh node report MESH. SourceName Name of the Worker that started the session. Only populated for Workers VPC sessions. SourceID Stable identifier of the Worker that started the session. Only populated for Workers VPC sessions. DestinationReplicaID The replica that served the session, such as a specific replica of a Mesh node or a cloudflared replica of a Cloudflare Tunnel.For example, OnrampType = 'WORKERS_VPC' AND Offramp = 'MESH' returns every session where a Worker reached a service behind a Mesh node, and SourceName tells you which Worker it was.
Redeploy your Workers
SourceName and SourceID are only populated for Workers deployed after 29 September 2026. To include them for an existing Worker, redeploy it — for example, with npx wrangler deploy. No code changes are required.
See which tunnel and replica received a session
With DestinationReplicaID, you can now confirm which Cloudflare Tunnel and which cloudflared replica received traffic for a specific session. Combine it with the existing DestinationTunnelID field to trace a session to an exact tunnel replica — or Mesh node replica — when you run multiple replicas for high availability. The replica ID matches the Connector ID shown in the dashboard, so you can stream that replica's logs with cloudflared tail --connector-id.
Sessions logged before this change are not backfilled. For all available fields, refer to Zero Trust Network Session Logs.
Original source Similar to Cloudflare One with recent updates:
- Cloudflare AI updates169 release notes · Latest Oct 2, 2026
- Claude updates151 release notes · Latest Oct 1, 2026
- Network Security updates35 release notes · Latest Sep 25, 2026
- Claude Code updates462 release notes · Latest Oct 4, 2026
- ChatGPT updates230 release notes · Latest Oct 2, 2026
- Gemini updates432 release notes · Latest Oct 2, 2026
- Sep 25, 2026
- Date parsed from source:Sep 25, 2026
- First seen by Releasebot:Sep 26, 2026
Cloudflare Network Firewall, Magic Transit, Cloudflare WAN - Managed Rulesets supported in Unified Routing
Cloudflare One adds Advanced Network Firewall Managed Rulesets support for Unified Routing mode.
Cloudflare Advanced Network Firewall Managed Rulesets are now supported for accounts using Unified Routing mode.
For the full list of feature availability, refer to Check feature availability before upgrading.
Original source - Sep 24, 2026
- Date parsed from source:Sep 24, 2026
- First seen by Releasebot:Sep 25, 2026
Access, Cloudflare One - MCP server portals are now generally available
Cloudflare One introduces generally available MCP server portals, giving customers a single endpoint for approved MCP servers with Access logging for tool, prompt, and resource activity. The update adds routing, DLP scanning, Code Mode policies, static OAuth credentials, session management, service tokens, and Logpush export.
MCP server portals are now generally available to all Cloudflare customers.
A portal gives users one endpoint for approved Model Context Protocol (MCP) servers. Cloudflare Access logs tool, prompt, and resource activity.
Since the open beta, MCP server portals have added:
- Gateway routing for HTTP logging and data loss prevention (DLP) scanning
- Code Mode policies that control how portals reduce tool definitions and token use
- Static OAuth client credentials for providers that do not support Dynamic Client Registration
- Session management for reconnecting servers and changing authorizations from the portal
- Service token authentication for autonomous agents and machine-to-machine access
- Logpush support for exporting portal activity to external storage or a security information and event management (SIEM) system
To create a portal and connect an MCP client, refer to MCP server portals.
Original source - Sep 23, 2026
- Date parsed from source:Sep 23, 2026
- First seen by Releasebot:Sep 24, 2026
Gateway, Cloudflare One - Traffic Destination selector in Gateway policies
Cloudflare One adds a Traffic Destination selector in Gateway HTTP and Network policies, letting administrators target how traffic exits Cloudflare. Policies can now distinguish off-ramp methods like Internet, Cloudflare Tunnel, Cloudflare WAN, device client, and Mesh.
Gateway HTTP and Network policies now include a Traffic Destination selector that identifies how traffic exits Cloudflare. This allows administrators to write policies that target specific off-ramp methods - for example, applying different rules to traffic destined for the public Internet compared to traffic routed through Cloudflare Tunnel or Cloudflare WAN.
Available traffic destination values
UI name
API value
Description
Internet
internet
Traffic to the public Internet
Cloudflare WAN
cloudflare_wan
Traffic through a Cloudflare WAN connection
Cloudflare Tunnel
cloudflare_tunnel
Traffic to a private origin through Cloudflare Tunnel
Cloudflare One Client
device_client
Traffic to another device running the Cloudflare One Client
Mesh
mesh
Traffic through a Cloudflare Mesh node
The selector uses the net.offramp.type API field in both HTTP and Network policies.
UI name
API example
Traffic Destination
net.offramp.type == "internet"
For more information, refer to HTTP policies and Network policies.
Original source - Sep 23, 2026
- Date parsed from source:Sep 23, 2026
- First seen by Releasebot:Sep 23, 2026
Cloudflare One, Cloudflare Mesh - Add Mesh participants with guided onboarding
Cloudflare One adds a faster Cloudflare Mesh dashboard for adding and managing participants, with new node deployment options, client installation guidance, and unified participant management in one table for easier search, filtering, and device details.
Cloudflare Mesh now makes it faster to add and manage participants from the dashboard. Select Add participant from Networking > Mesh to deploy a Mesh node or find the information needed to connect a client device.
The updated dashboard includes the following improvements:
More Mesh node deployment options
Install a node on Linux, Kubernetes, Docker Compose, or Docker CLI. The dashboard provides requirements, commands, configuration, and links for each method. Refer to Run Mesh in Docker / Kubernetes for container deployment details.
Client device installation guidance
Access platform-specific Cloudflare One Client installers, mobile QR codes, and your Cloudflare One organization name. Use the organization name to log in from the client after installation.
Unified participant management
View Mesh nodes and enrolled client devices in one table. Search devices, filter participants by type or status, open device details, and load additional results from each participant source. If one source fails, participants from the other source remain available while you retry the request.
You must still install the Cloudflare One Client, log in to your organization, and test the connection.
For complete setup instructions, refer to Get started with Cloudflare Mesh.
Original source - Sep 22, 2026
- Date parsed from source:Sep 22, 2026
- First seen by Releasebot:Sep 22, 2026
Access - Automatically manage inactive Access service tokens
Cloudflare One adds automatic cleanup for inactive Access service tokens, letting administrators disable or delete tokens after 30 to 365 days of inactivity to better reduce stale access risk.
Cloudflare Access administrators can now automatically disable or delete inactive service tokens.
Administrators can set an inactivity period from 30 to 365 days and choose what Access does when a token reaches that limit.
To be eligible for cleanup, a token must be older than the configured period, must not have successfully authenticated during that period, and must not be directly referenced by an Access policy rule. Cleanup runs gradually in the background, so eligible tokens may not be disabled or deleted immediately.
For configuration instructions, refer to Manage inactive service tokens.
Original source - Sep 18, 2026
- Date parsed from source:Sep 18, 2026
- First seen by Releasebot:Oct 2, 2026
Cloudflare Tunnel, Cloudflare Tunnel for SASE - cloudflared to deprecate 32-bit Windows and Intel-based macOS builds in 2027
Cloudflare One announces a future cloudflared deprecation for 32-bit Windows and Intel-based macOS builds, aligning support with modern operating systems and focusing updates on currently supported platforms.
Starting in 2027, Cloudflare will deprecate 32-bit Windows and Intel-based macOS builds of cloudflared. After the deprecation takes effect, Cloudflare will no longer publish new cloudflared releases for either architecture.
Windows 10, the last Windows release to support 32-bit systems, reached end of support in October 2025. Apple has also deprecated Intel-based Mac computers. macOS 26 Tahoe, released in September 2025, was the final macOS release to support Intel-based Macs. macOS 27, released in September 2026, no longer supports them.
Focusing development on currently supported architectures allows cloudflared to align with operating system support and continue receiving updates on supported platforms. For available downloads and supported platforms, refer to the Cloudflare Tunnel downloads documentation.
Original source - Sep 18, 2026
- Date parsed from source:Sep 18, 2026
- First seen by Releasebot:Sep 19, 2026
Cloudflare WAN, Magic Transit, Cloudflare One - Unified Routing generally available
Cloudflare One adds Unified Routing GA for Cloudflare WAN and Magic Transit with Automatic Return Routing and BGP support.
Unified Routing is generally available for Cloudflare WAN and Magic Transit.
Unified Routing improves the integration between Cloudflare One and the standard connectivity onramps supported by Cloudflare WAN. It is capable of many new features including Automatic Return Routing, BGP and custom client subnets.
We recommend Unified Routing for all new accounts.
For details, refer to Cloudflare WAN traffic steering and Magic Transit traffic steering.
Original source - Sep 15, 2026
- Date parsed from source:Sep 15, 2026
- First seen by Releasebot:Sep 17, 2026
Cloudflare One, Access - Access for Infrastructure now supports tagged targets and tag-based target criteria
Cloudflare One adds Resource Tagging to Access for Infrastructure, letting teams tag infrastructure targets with key-value labels and use them in access policies. It also introduces target criteria controls with include, require, and exclude operators for more precise matching.
Access for Infrastructure now integrates with Resource Tagging. You can attach key-value tags to infrastructure targets and use them in access policies.
You can manage tags on targets inline when you create or edit a target or through the central Resource Tagging API. Cloudflare keeps tags in sync across both methods.
Infrastructure applications also support a target criteria model with include, require, and exclude operators. Each operator can match targets by hostname, tag, or both.
Include matches targets that have any of the specified values.
Require matches targets that have all of the specified values.
Exclude rejects targets that have any of the specified values.
For more information, refer to Add an infrastructure application.
Original source - Sep 14, 2026
- Date parsed from source:Sep 14, 2026
- First seen by Releasebot:Sep 14, 2026
Access - Require fresh authentication for SAML identity providers
Cloudflare One adds fresh SAML reauthentication for Access logins.
Cloudflare Access can now request fresh authentication from a SAML identity provider for every login. Turn on Require reauthentication in the Cloudflare dashboard, or set force_authn to true through the API. Access will then set ForceAuthn to true in signed and unsigned SAML authentication requests.
This option is useful when an application requires users to reauthenticate at the identity provider instead of relying on an existing identity provider session. The default value is false.
For configuration details, refer to Require fresh authentication at the identity provider.
Original source - Sep 14, 2026
- Date parsed from source:Sep 14, 2026
- First seen by Releasebot:Sep 14, 2026
Data Loss Prevention - Discover where sensitive data goes before you create a Data Loss Prevention policy
Cloudflare One adds Passive Detection for Data Loss Prevention, giving teams visibility into sensitive data in Gateway traffic before they decide what to log or block. The dashboard helps explore sampled HTTP bodies, destinations, policy coverage, and trends, and it is generally available.
Passive Detection for Cloudflare Data Loss Prevention (DLP) lets you learn from your Gateway traffic before deciding what to log or block. Discover the sensitive data types in sampled traffic, explore their destinations, and use the findings to build policies around your organization's needs.
The dashboard brings together detections from sampled HTTP request and response bodies. Select an entry to follow its detections over time, review destinations, and check policy coverage. You do not need a Gateway DLP policy to get these insights, and existing Gateway policies continue to apply.
Passive Detection is generally available. The detection entries available to your account depend on your Zero Trust plan.
To get started, refer to the Passive Detection documentation.
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.