From Cloudflare Blog · 14 stories
Critical WordPress Vulnerabilities Exploited, Urgent Patching Advised
Two critical vulnerabilities, CVE-2026-60137 and CVE-2026-63030, in WordPress Core are being actively exploited, affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. These 'wp2shell' flaws allow remote code execution through anonymous requests, prompting WordPress to issue updates 6.9.5 and 7.0.2 on July 17, 2026, with forced auto-updates enabled. Cloudflare has deployed Web Application Firewall protections to mitigate the risk while users apply patches.
Cloudflare and Patreon Partner to Block Unauthorized AI Crawlers and Monetize Content
Cloudflare announced updates to their policies and tools, including blocking mixed-use AI crawlers by default from September 15, 2026, to help website owners manage AI traffic and monetize their content. Patreon has joined forces with Cloudflare to block AI crawlers from accessing creator content. The move aligns with industry shifts towards AI-dominated web traffic and aims to protect content owners' intellectual property.
U.S. Executive Order Mandates Post-Quantum Encryption by 2030
President Trump signed Executive Order 14412, requiring federal agencies to transition to post-quantum encryption by December 31, 2030, and authentication by December 31, 2031. This move addresses the imminent threat quantum computing poses to traditional cryptographic systems, stimulating the broader tech industry's shift towards post-quantum technologies.
The Impact of the 2026 World Cup on Global Internet Traffic Patterns
The 2026 World Cup significantly reshaped online traffic patterns as fans adjusted their routines around matches. Using Cloudflare Radar data, the analysis reveals how kick-off times affected internet activity globally throughout the tournament.
Cloudflare Internal DNS Launches for Private Networks
Cloudflare has launched its Internal DNS, providing unified management of authoritative and recursive DNS for private networks. This service aims to simplify DNS operations by consolidating public and private DNS management on a single platform, thereby enhancing security and visibility across networks.
Albania's .al TLD DNSSEC failure led to validation issues for Cloudflare's 1.1.1.1
On July 3, 2026, Albania's .al TLD experienced DNSSEC validation failures due to a key rollover error, blocking public access to various domains. Cloudflare's 1.1.1.1 responded by bypassing DNSSEC validation, introducing a new error notification to users about this change.
Cloudflare Enhances Smart Tiered Cache for Better Public Cloud Performance
Cloudflare has improved its Smart Tiered Cache to better serve public cloud origins by allowing users to provide a cloud region hint. This development enhances the system's efficiency, enabling more accurate routing and cache selection even for ambiguous origin IPs.
Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA
Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.
Cloudflare joins UK's Cyber Resilience Pledge to enhance cybersecurity governance
The UK government launched the Cyber Resilience Pledge, aimed at enhancing cybersecurity governance. Cloudflare joined as a founding signatory, emphasizing collective defense principles against increasing cyber threats.
New Controls for AI Bots Target Search Economic Model Rebuild
A new set of bot controls was announced to aid web creators in managing AI's impact on search traffic. These measures aim to ensure transparency and uphold existing revenue models disrupted by AI-generated summaries, which have drastically reduced traditional link clicks.
Cloudflare Introduces Saga Rollbacks for Workflows
Cloudflare has launched saga rollbacks for Workflows, enabling developers to implement compensation logic directly within each step of a multi-step application. This feature simplifies transaction management by allowing automatic rollbacks for failed steps, reducing the need for developers to manually track and implement their own rollback logic.
Cloudflare Introduces Self-Managed OAuth for API Access
Cloudflare has announced self-managed OAuth for its API, allowing all developers to create and manage OAuth clients. This change simplifies the process of granting scoped access for integrations, enhancing user consent and application control.
Cloudflare identifies race condition bug in hyper HTTP library
Cloudflare discovered a race condition bug in the hyper HTTP library affecting its Images service. This bug caused data for larger images to be truncated in transformation requests, leading to intermittent failures.
Cloudflare Introduces Temporary Accounts for AI Agent Deployments
Cloudflare has launched Temporary Accounts for AI agents, allowing them to deploy without prior registration. This enhancement facilitates seamless deployments, addressing a significant roadblock for background AI sessions that currently rely on human authentication.