Skip to content

Changelog

New updates and improvements at Cloudflare.

Back to all posts

WAF Release - 2026-08-25

This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode.

Key Findings

  • Four new detections move from Log to Block: HTTP/2 Request Smuggling - Request Body Anomaly and XSS - JavaScript Event Handler Coercion across Headers, Body, and URI.

  • The XSS, HTML Injection - Script Tag - Beta rule is merged into the original rule.

  • A Generic Rules - Remote Code Execution detection is added in Block mode.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AHTTP/2 Request Smuggling - Request Body AnomalyLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS - JavaScript Event Handler Coercion - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS - JavaScript Event Handler Coercion - BodyLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS - JavaScript Event Handler Coercion - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS, HTML Injection - Script Tag - BetaLogBlockThis rule is merged into the original rule "XSS, HTML Injection - Script Tag" (ID: ).
Cloudflare Managed RulesetN/AGeneric Rules - Remote Code ExecutionN/ABlockThis is a new detection.