Skip to content
Cloudflare Docs

Historical (2024)

Managed ruleset updates

RulesetRule IDLegacy Rule IDDescriptionChange DateOld ActionNew Action
Cloudflare Specials 100675Adobe ColdFusion - Auth Bypass - CVE:CVE-2023-382052024-10-21LogBlock
Cloudflare Specials 100676Palo Alto Networks - Auth Bypass - CVE:CVE-2024-59102024-10-21LogBlock
Cloudflare Specials 100677SolarWinds - Auth Bypass - CVE:CVE-2024-289872024-10-21LogBlock
Cloudflare Specials 100673GoAnywhere - Remote Code Execution - CVE:CVE-2023-06692024-10-14LogBlock
Cloudflare Specials 100669

Apache HugeGraph-Server - Remote Code Execution - CVE:CVE-2024-27348

2024-10-07LogBlock
Cloudflare Specials 100672Ivanti Virtual Traffic Manager - Auth Bypass - CVE:CVE-2024-75932024-10-07LogBlock
Cloudflare Specials 100670Junos - Remote Code Execution - CVE:CVE-2023-368442024-10-07LogBlock
Cloudflare Specials 100671Microsoft SQL Server - Remote Code Execution - CVE:CVE-2020-06182024-10-07LogBlock
Cloudflare Specials 100581Joomla - Information Disclosure - CVE:CVE-2023-237522024-10-07LogBlock
Cloudflare Specials 100668

Progress Software WhatsUp Gold - Information Disclosure - CVE:CVE-2024-6670

2024-10-01LogBlock
Cloudflare Specials N/AAnomaly:Body - Large 22024-09-16N/ADisabled
Cloudflare Specials 100526VMware vCenter - CVE:CVE-2022-22954, CVE:CVE-2022-229482024-09-03N/ABlock
Cloudflare Specials 100667Authentik - Auth Bypass - CVE:CVE-2024-42490Emergency, 2024-08-20N/ABlock
Cloudflare Specials 100666Apache OFBiz - Remote Code Execution - CVE:CVE-2024-321132024-08-19LogBlock
Cloudflare Specials 100665Zoho ManageEngine - Remote Code Execution - CVE:CVE-2023-290842024-08-19LogBlock
Cloudflare Specials 100664Automation Anywhere - SSRF - CVE:CVE-2024-69222024-08-05LogBlock
Cloudflare Specials 100663WSO2 - Dangerous File Upload - CVE:CVE-2022-294642024-08-05LogBlock
Cloudflare Specials 100662

ServiceNow - Input Validation - CVE:CVE-2024-4879, CVE:CVE-2024-5178, CVE:CVE-2024-5217

2024-08-05LogBlock
Cloudflare Specials 100659Common Payloads for Server-side Template Injection - Base642024-07-29N/ADisabled
Cloudflare Specials 100559APrototype Pollution - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials 100660Server-side Includes - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials 100661SQLi - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials 100524Java - Remote Code Execution2024-07-29BlockDisabled
Cloudflare Specials 100524Java - Remote Code Execution2024-07-24LogBlock
Cloudflare Specials 100659Common Payloads for Server-side Template Injection2024-07-24N/ADisabled
Cloudflare Specials 100533AGeneric Payloads NoSQL Injection Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials 100533AGeneric Payloads NoSQL Injection2024-07-24N/ADisabled
Cloudflare Specials 100644Generic Payloads XSS Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials 100644Generic Payloads XSS2024-07-24N/ADisabled
Cloudflare Specials 100642LDAP Injection Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials 100642LDAP Injection2024-07-24N/ADisabled
Cloudflare Specials 100559APrototype Pollution - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials 100645Remote Code Execution - Generic Payloads2024-07-24N/ADisabled
Cloudflare Specials 100660Server-Side Includes - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials 100661SQLi - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials 100658Apache OFBiz - SSRF - CVE:CVE-2023-509682024-07-17LogBlock
Cloudflare Specials 100657JEECG - Deserialization - CVE:CVE-2023-494422024-07-17LogBlock
Cloudflare Specials 100532Vulnerability scanner activity2024-07-17LogBlock
Cloudflare Specials 100654

Telerik Report Server - Auth Bypass - CVE:CVE-2024-4358, CVE:CVE-2024-1800

2024-07-10LogBlock
Cloudflare Specials 100655

Rejetto HTTP File Server - Remote Code Execution - CVE:CVE-2024-23692

2024-07-10LogBlock
Cloudflare Specials 100647pgAdmin - Remote Code Execution - CVE:CVE-2024-31162024-07-10LogBlock
Cloudflare Specials 100656MoveIT - Auth Bypass - CVE:CVE-2024-58062024-07-10LogBlock
Cloudflare Specials 100079AJava - Deserialization - 22024-07-10LogBlock
Cloudflare Specials 100648Groovy - Remote Code Execution2024-07-10LogBlock
Cloudflare Specials 100700Apache SSRF vulnerability CVE-2021-404382024-07-10LogBlock
Cloudflare Specials 100652PHP CGI - Information Disclosure - CVE:CVE-2024-4577Emergency, 2024-06-18N/ABlock
Cloudflare Specials 100653

Veeam Backup Enterprise Manager - Information Disclosure - CVE:CVE-2024-29849

Emergency, 2024-06-18N/ABlock
Cloudflare Specials 100651Atlassian Confluence - Remote Code Execution - CVE:CVE-2024-21683Emergency, 2024-06-06N/ABlock
Cloudflare Specials 100650

Check Point Security - Information Disclosure - CVE:CVE-2024-24919

Emergency, 2024-05-30N/ABlock
Cloudflare Specials 100649

FortiSIEM - Remote Code Execution - CVE:CVE-2024-23108, CVE:CVE-2023-34992

Emergency, 2024-05-29N/ABlock
Cloudflare Specials N/AGeneric Payloads XSS Base64 2 Beta2024-05-21N/ADisabled
Cloudflare Specials N/AGeneric Payloads NoSQL Injection Base64 Beta2024-05-14N/ADisabled
Cloudflare Specials N/ALDAP Injection Base64 Beta2024-05-14N/ADisabled
Cloudflare Specials N/ANoSQL - Injection Base64 2 Beta2024-05-14N/ADisabled
Cloudflare Specials N/AGeneric Payloads XSS Base64 Beta2024-05-08N/ADisabled
Cloudflare Specials 100532Vulnerability scanner activity2024-05-06N/ABlock
Cloudflare Specials 100533NoSQL - Injection2024-05-06N/ABlock
Sensitive Data Disclosure (SDD) N/AMalaysian Phone Number2024-04-24N/ADisabled
Sensitive Data Disclosure (SDD) N/A Malaysia Identification Card Number2024-04-24N/ADisabled
Cloudflare Specials N/AVulnerability scanner activity 3 Base64 Beta2024-04-24N/ADisabled
Cloudflare Specials N/ADefault Windows User - Directory Traversal Base64 Beta2024-04-24N/ADisabled
Cloudflare Specials N/AGeneric Payloads NoSQL Injection Base64 Beta2024-04-24N/ADisabled
Cloudflare Specials N/ANoSQL - Injection Base64 2 Beta2024-04-24N/ADisabled
Cloudflare Specials N/ALDAP Injection Base64 Beta2024-04-24N/ADisabled
Cloudflare Specials 100645Remote Code Execution - Generic Payloads2024-04-22N/ADisabled
Cloudflare Specials 100533AGeneric Payloads NoSQL Injection2024-04-22N/ADisabled
Cloudflare Specials 100644Generic Payloads XSS2024-04-22N/ADisabled
Cloudflare Specials 100007C_BETA

Command Injection - Common Attack Commands Beta

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials 100643

Default Windows User - Directory Traversal

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials 100642

LDAP Injection

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials 100532C

Vulnerability scanner activity 3

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials 100007CCommand Injection - Common Attack CommandsEmergency, 2024-04-16N/ABlock
Cloudflare Specials 100045C

Anomaly:URL:Path - Multiple Slashes, Relative Paths, CR, LF or NULL 2

2024-04-15N/ADisabled
Cloudflare Specials 100007C_BETACommand Injection - Common Attack Commands Beta2024-04-15N/ADisabled
Cloudflare Specials 100643Default Windows User - Directory Traversal2024-04-15N/ADisabled
Cloudflare Specials 100088EGeneric XXE Attack2024-04-15N/ADisabled
Cloudflare Specials 100088DGeneric XXE Attack 22024-04-15N/ADisabled
Cloudflare Specials 100536AGraphQL Introspection2024-04-15N/ADisabled
Cloudflare Specials 100536BGraphQL SSRF2024-04-15N/ADisabled
Cloudflare Specials 100642LDAP Injection2024-04-15N/ADisabled
Cloudflare Specials 100532CVulnerability scanner activity 32024-04-15N/ADisabled
Cloudflare Specials 100632Nginx - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100633PHP - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100634Generic Database - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100635Generic Log - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100636Generic Webservers - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100637Generic Home Directory - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100638Generic System Process - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100639Command Injection2024-04-08N/ADisabled
Cloudflare Specials 100640Generic System - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100641Apache - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials 100629

JetBrains TeamCity - Auth Bypass, Remote Code Execution - CVE:CVE-2024-27198, CVE:CVE-2024-27199

2024-03-18N/ABlock
Cloudflare Specials 100630

Apache OFBiz - Auth Bypass, Remote Code Execution - CVE:CVE-2023-49070, CVE:CVE-2023-51467

2024-03-18N/ABlock
Cloudflare Specials 100627

Wordpress:Plugin:Bricks Builder Theme - Command Injection - CVE:CVE-2024-25600

2024-03-11N/ABlock
Cloudflare Specials 100628ConnectWise - Auth Bypass2024-03-11N/ABlock
Cloudflare Specials 100135DXSS - JS On Events2024-03-04N/ABlock
Cloudflare Specials 100546XSS - HTML Encoding2024-02-26N/ABlock
Cloudflare Specials 100622B, 100622C

Ivanti - Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887, CVE:CVE-2024-22024

2024-02-20N/ABlock
Cloudflare Specials N/AMicrosoft ASP.NET - Code Injection - Function response.write2024-02-20N/ABlock
Cloudflare Specials N/ANoSQL, MongoDB - SQLi - Comparison2024-02-20N/ABlock
Cloudflare Specials N/ANoSQL, MongoDB - SQLi - Expression2024-02-20N/ABlock
Cloudflare Specials N/APHP - Code Injection2024-02-20N/ADisabled
Cloudflare Specials N/A

PHP, vBulletin, jQuery File Upload - Code Injection, Dangerous File Upload - CVE:CVE-2018-9206, CVE:CVE-2019-17132

2024-02-20N/ABlock
Cloudflare Specials 100625Jenkins - Information Disclosure - CVE:CVE-2024-238972024-02-12N/ABlock
Cloudflare Specials 100514Log4j Headers2024-02-12N/ABlock
Cloudflare Specials 100515BLog4j Body Obfuscation2024-02-12N/ABlock
Cloudflare Specials 100624GoAnywhere - Auth Bypass - CVE:CVE-2024-02042024-02-05N/ABlock
Cloudflare Specials 100626,100626AAnomaly:Header:Content-Type - Multiple2024-02-05N/ADisabled
Cloudflare Specials N/AAngularJS - XSS2024-02-05N/ABlock
Cloudflare Specials N/AApache HTTP Server - Server-Side Includes2024-02-05N/ADisabled
Cloudflare Specials N/ACommand Injection - CVE:CVE-2014-62712024-02-05N/ABlock
Cloudflare Specials N/ACommand Injection - Nslookup2024-02-05N/ABlock
Cloudflare Specials N/AMicrosoft ASP.NET - Code Injection2024-02-05N/ADisabled
Cloudflare Specials 100623Atlassian Confluence - Template Injection - CVE:CVE-2023-22527Emergency, 2024-01-22N/ABlock
Cloudflare Specials 100622

Ivanti - Auth Bypass, Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887

Emergency, 2024-01-17N/ABlock
Cloudflare Specials 100620Microsoft ASP.NET - Remote Code Execution - CVE:CVE-2023-358132024-01-16N/ABlock
Cloudflare Specials 100619Liferay - Remote Code Execution - CVE:CVE-2020-79612024-01-16N/ABlock
Cloudflare Specials 100618pfSense - Remote Code Execution - CVE:CVE-2023-423262024-01-16N/ABlock
Cloudflare Specials 100621Clerk - Auth Bypass2024-01-16N/ADisabled
Cloudflare Specials 100612SnakeYAML - CVE:CVE-2022-14712024-01-04N/ABlock

General updates

2024-12-18

Improved VPN Managed List

Customers can now effectively manage incoming traffic identified as originating from VPN IPs. Customers with compliance restrictions can now ensure compliance with local laws and regulations. Customers with CDN restrictions can use the improved VPN Managed List to prevent unauthorized access from users attempting to bypass geographical restrictions. With the new VPN Managed List enhancements, customers can improve their overall security posture to reduce exposure to unwanted or malicious traffic.

2024-12-10

Change the order of list items in IP Lists (for API and Terraform users)

Due to changes in the API implementation, the order of list items in an IP list obtained via API or Terraform may change, which may cause Terraform to detect a change in Terraform state. To fix this issue, resync the Terraform state or upgrade the version of your Terraform Cloudflare provider to version 4.44.0 or later.

2024-11-14

Security Events pagination

Fixed an issue with pagination in Security Events' sampled logs where some pages were missing data. Also removed the total count from the events log as these are only sampled logs.

2024-11-04

New table in Security Analytics and Security Events

Switched to a new, more responsive table in Security Analytics and Security Events.

2024-08-29

Fixed occasional attack score mismatches

Fixed an issue causing score mismatches between the global WAF attack score and subscores. In certain cases, subscores were higher (not an attack) than expected while the global attack score was lower than expected (attack), leading to false positives.

2024-05-23

Improved detection capabilities

WAF attack score now automatically detects and decodes Base64 and JavaScript (Unicode escape sequences) in HTTP requests. This update is available for all customers with access to WAF attack score (Business customers with access to a single field and Enterprise customers).