Skip to content

Historical (2024)

Last updated View as MarkdownAgent setup

Managed ruleset updates

RulesetRule IDLegacy Rule IDDescriptionChange DateOld ActionNew Action
Cloudflare Specials100675Adobe ColdFusion - Auth Bypass - CVE:CVE-2023-382052024-10-21LogBlock
Cloudflare Specials100676Palo Alto Networks - Auth Bypass - CVE:CVE-2024-59102024-10-21LogBlock
Cloudflare Specials100677SolarWinds - Auth Bypass - CVE:CVE-2024-289872024-10-21LogBlock
Cloudflare Specials100673GoAnywhere - Remote Code Execution - CVE:CVE-2023-06692024-10-14LogBlock
Cloudflare Specials100669

Apache HugeGraph-Server - Remote Code Execution - CVE:CVE-2024-27348

2024-10-07LogBlock
Cloudflare Specials100672Ivanti Virtual Traffic Manager - Auth Bypass - CVE:CVE-2024-75932024-10-07LogBlock
Cloudflare Specials100670Junos - Remote Code Execution - CVE:CVE-2023-368442024-10-07LogBlock
Cloudflare Specials100671Microsoft SQL Server - Remote Code Execution - CVE:CVE-2020-06182024-10-07LogBlock
Cloudflare Specials100581Joomla - Information Disclosure - CVE:CVE-2023-237522024-10-07LogBlock
Cloudflare Specials100668

Progress Software WhatsUp Gold - Information Disclosure - CVE:CVE-2024-6670

2024-10-01LogBlock
Cloudflare SpecialsN/AAnomaly:Body - Large 22024-09-16N/ADisabled
Cloudflare Specials100526VMware vCenter - CVE:CVE-2022-22954, CVE:CVE-2022-229482024-09-03N/ABlock
Cloudflare Specials100667Authentik - Auth Bypass - CVE:CVE-2024-42490Emergency, 2024-08-20N/ABlock
Cloudflare Specials100666Apache OFBiz - Remote Code Execution - CVE:CVE-2024-321132024-08-19LogBlock
Cloudflare Specials100665Zoho ManageEngine - Remote Code Execution - CVE:CVE-2023-290842024-08-19LogBlock
Cloudflare Specials100664Automation Anywhere - SSRF - CVE:CVE-2024-69222024-08-05LogBlock
Cloudflare Specials100663WSO2 - Dangerous File Upload - CVE:CVE-2022-294642024-08-05LogBlock
Cloudflare Specials100662

ServiceNow - Input Validation - CVE:CVE-2024-4879, CVE:CVE-2024-5178, CVE:CVE-2024-5217

2024-08-05LogBlock
Cloudflare Specials100659Common Payloads for Server-side Template Injection - Base642024-07-29N/ADisabled
Cloudflare Specials100559APrototype Pollution - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials100660Server-side Includes - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials100661SQLi - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials100524Java - Remote Code Execution2024-07-29BlockDisabled
Cloudflare Specials100524Java - Remote Code Execution2024-07-24LogBlock
Cloudflare Specials100659Common Payloads for Server-side Template Injection2024-07-24N/ADisabled
Cloudflare Specials100533AGeneric Payloads NoSQL Injection Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials100533AGeneric Payloads NoSQL Injection2024-07-24N/ADisabled
Cloudflare Specials100644Generic Payloads XSS Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials100644Generic Payloads XSS2024-07-24N/ADisabled
Cloudflare Specials100642LDAP Injection Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials100642LDAP Injection2024-07-24N/ADisabled
Cloudflare Specials100559APrototype Pollution - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials100645Remote Code Execution - Generic Payloads2024-07-24N/ADisabled
Cloudflare Specials100660Server-Side Includes - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials100661SQLi - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials100658Apache OFBiz - SSRF - CVE:CVE-2023-509682024-07-17LogBlock
Cloudflare Specials100657JEECG - Deserialization - CVE:CVE-2023-494422024-07-17LogBlock
Cloudflare Specials100532Vulnerability scanner activity2024-07-17LogBlock
Cloudflare Specials100654

Telerik Report Server - Auth Bypass - CVE:CVE-2024-4358, CVE:CVE-2024-1800

2024-07-10LogBlock
Cloudflare Specials100655

Rejetto HTTP File Server - Remote Code Execution - CVE:CVE-2024-23692

2024-07-10LogBlock
Cloudflare Specials100647pgAdmin - Remote Code Execution - CVE:CVE-2024-31162024-07-10LogBlock
Cloudflare Specials100656MoveIT - Auth Bypass - CVE:CVE-2024-58062024-07-10LogBlock
Cloudflare Specials100079AJava - Deserialization - 22024-07-10LogBlock
Cloudflare Specials100648Groovy - Remote Code Execution2024-07-10LogBlock
Cloudflare Specials100700Apache SSRF vulnerability CVE-2021-404382024-07-10LogBlock
Cloudflare Specials100652PHP CGI - Information Disclosure - CVE:CVE-2024-4577Emergency, 2024-06-18N/ABlock
Cloudflare Specials100653

Veeam Backup Enterprise Manager - Information Disclosure - CVE:CVE-2024-29849

Emergency, 2024-06-18N/ABlock
Cloudflare Specials100651Atlassian Confluence - Remote Code Execution - CVE:CVE-2024-21683Emergency, 2024-06-06N/ABlock
Cloudflare Specials100650

Check Point Security - Information Disclosure - CVE:CVE-2024-24919

Emergency, 2024-05-30N/ABlock
Cloudflare Specials100649

FortiSIEM - Remote Code Execution - CVE:CVE-2024-23108, CVE:CVE-2023-34992

Emergency, 2024-05-29N/ABlock
Cloudflare SpecialsN/AGeneric Payloads XSS Base64 2 Beta2024-05-21N/ADisabled
Cloudflare SpecialsN/AGeneric Payloads NoSQL Injection Base64 Beta2024-05-14N/ADisabled
Cloudflare SpecialsN/ALDAP Injection Base64 Beta2024-05-14N/ADisabled
Cloudflare SpecialsN/ANoSQL - Injection Base64 2 Beta2024-05-14N/ADisabled
Cloudflare SpecialsN/AGeneric Payloads XSS Base64 Beta2024-05-08N/ADisabled
Cloudflare Specials100532Vulnerability scanner activity2024-05-06N/ABlock
Cloudflare Specials100533NoSQL - Injection2024-05-06N/ABlock
Sensitive Data Disclosure (SDD)N/AMalaysian Phone Number2024-04-24N/ADisabled
Sensitive Data Disclosure (SDD)N/A Malaysia Identification Card Number2024-04-24N/ADisabled
Cloudflare SpecialsN/AVulnerability scanner activity 3 Base64 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/ADefault Windows User - Directory Traversal Base64 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/AGeneric Payloads NoSQL Injection Base64 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/ANoSQL - Injection Base64 2 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/ALDAP Injection Base64 Beta2024-04-24N/ADisabled
Cloudflare Specials100645Remote Code Execution - Generic Payloads2024-04-22N/ADisabled
Cloudflare Specials100533AGeneric Payloads NoSQL Injection2024-04-22N/ADisabled
Cloudflare Specials100644Generic Payloads XSS2024-04-22N/ADisabled
Cloudflare Specials100007C_BETA

Command Injection - Common Attack Commands Beta

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials100643

Default Windows User - Directory Traversal

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials100642

LDAP Injection

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials100532C

Vulnerability scanner activity 3

Updated detection logic.

2024-04-22N/ADisabled
Cloudflare Specials100007CCommand Injection - Common Attack CommandsEmergency, 2024-04-16N/ABlock
Cloudflare Specials100045C

Anomaly:URL:Path - Multiple Slashes, Relative Paths, CR, LF or NULL 2

2024-04-15N/ADisabled
Cloudflare Specials100007C_BETACommand Injection - Common Attack Commands Beta2024-04-15N/ADisabled
Cloudflare Specials100643Default Windows User - Directory Traversal2024-04-15N/ADisabled
Cloudflare Specials100088EGeneric XXE Attack2024-04-15N/ADisabled
Cloudflare Specials100088DGeneric XXE Attack 22024-04-15N/ADisabled
Cloudflare Specials100536AGraphQL Introspection2024-04-15N/ADisabled
Cloudflare Specials100536BGraphQL SSRF2024-04-15N/ADisabled
Cloudflare Specials100642LDAP Injection2024-04-15N/ADisabled
Cloudflare Specials100532CVulnerability scanner activity 32024-04-15N/ADisabled
Cloudflare Specials100632Nginx - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100633PHP - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100634Generic Database - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100635Generic Log - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100636Generic Webservers - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100637Generic Home Directory - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100638Generic System Process - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100639Command Injection2024-04-08N/ADisabled
Cloudflare Specials100640Generic System - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100641Apache - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100629

JetBrains TeamCity - Auth Bypass, Remote Code Execution - CVE:CVE-2024-27198, CVE:CVE-2024-27199

2024-03-18N/ABlock
Cloudflare Specials100630

Apache OFBiz - Auth Bypass, Remote Code Execution - CVE:CVE-2023-49070, CVE:CVE-2023-51467

2024-03-18N/ABlock
Cloudflare Specials100627

Wordpress:Plugin:Bricks Builder Theme - Command Injection - CVE:CVE-2024-25600

2024-03-11N/ABlock
Cloudflare Specials100628ConnectWise - Auth Bypass2024-03-11N/ABlock
Cloudflare Specials100135DXSS - JS On Events2024-03-04N/ABlock
Cloudflare Specials100546XSS - HTML Encoding2024-02-26N/ABlock
Cloudflare Specials100622B, 100622C

Ivanti - Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887, CVE:CVE-2024-22024

2024-02-20N/ABlock
Cloudflare SpecialsN/AMicrosoft ASP.NET - Code Injection - Function response.write2024-02-20N/ABlock
Cloudflare SpecialsN/ANoSQL, MongoDB - SQLi - Comparison2024-02-20N/ABlock
Cloudflare SpecialsN/ANoSQL, MongoDB - SQLi - Expression2024-02-20N/ABlock
Cloudflare SpecialsN/APHP - Code Injection2024-02-20N/ADisabled
Cloudflare SpecialsN/A

PHP, vBulletin, jQuery File Upload - Code Injection, Dangerous File Upload - CVE:CVE-2018-9206, CVE:CVE-2019-17132

2024-02-20N/ABlock
Cloudflare Specials100625Jenkins - Information Disclosure - CVE:CVE-2024-238972024-02-12N/ABlock
Cloudflare Specials100514Log4j Headers2024-02-12N/ABlock
Cloudflare Specials100515BLog4j Body Obfuscation2024-02-12N/ABlock
Cloudflare Specials100624GoAnywhere - Auth Bypass - CVE:CVE-2024-02042024-02-05N/ABlock
Cloudflare Specials100626,100626AAnomaly:Header:Content-Type - Multiple2024-02-05N/ADisabled
Cloudflare SpecialsN/AAngularJS - XSS2024-02-05N/ABlock
Cloudflare SpecialsN/AApache HTTP Server - Server-Side Includes2024-02-05N/ADisabled
Cloudflare SpecialsN/ACommand Injection - CVE:CVE-2014-62712024-02-05N/ABlock
Cloudflare SpecialsN/ACommand Injection - Nslookup2024-02-05N/ABlock
Cloudflare SpecialsN/AMicrosoft ASP.NET - Code Injection2024-02-05N/ADisabled
Cloudflare Specials100623Atlassian Confluence - Template Injection - CVE:CVE-2023-22527Emergency, 2024-01-22N/ABlock
Cloudflare Specials100622

Ivanti - Auth Bypass, Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887

Emergency, 2024-01-17N/ABlock
Cloudflare Specials100620Microsoft ASP.NET - Remote Code Execution - CVE:CVE-2023-358132024-01-16N/ABlock
Cloudflare Specials100619Liferay - Remote Code Execution - CVE:CVE-2020-79612024-01-16N/ABlock
Cloudflare Specials100618pfSense - Remote Code Execution - CVE:CVE-2023-423262024-01-16N/ABlock
Cloudflare Specials100621Clerk - Auth Bypass2024-01-16N/ADisabled
Cloudflare Specials100612SnakeYAML - CVE:CVE-2022-14712024-01-04N/ABlock

General updates

2024-12-18

Improved VPN Managed List

Customers can now effectively manage incoming traffic identified as originating from VPN IPs. Customers with compliance restrictions can now ensure compliance with local laws and regulations. Customers with CDN restrictions can use the improved VPN Managed List to prevent unauthorized access from users attempting to bypass geographical restrictions. With the new VPN Managed List enhancements, customers can improve their overall security posture to reduce exposure to unwanted or malicious traffic.

2024-12-10

Change the order of list items in IP Lists (for API and Terraform users)

Due to changes in the API implementation, the order of list items in an IP list obtained via API or Terraform may change, which may cause Terraform to detect a change in Terraform state. To fix this issue, resync the Terraform state or upgrade the version of your Terraform Cloudflare provider to version 4.44.0 or later.

2024-11-14

Security Events pagination

Fixed an issue with pagination in Security Events' sampled logs where some pages were missing data. Also removed the total count from the events log as these are only sampled logs.

2024-11-04

New table in Security Analytics and Security Events

Switched to a new, more responsive table in Security Analytics and Security Events.

2024-08-29

Fixed occasional attack score mismatches

Fixed an issue causing score mismatches between the global WAF attack score and subscores. In certain cases, subscores were higher (not an attack) than expected while the global attack score was lower than expected (attack), leading to false positives.

2024-05-23

Improved detection capabilities

WAF attack score now automatically detects and decodes Base64 and JavaScript (Unicode escape sequences) in HTTP requests. This update is available for all customers with access to WAF attack score (Business customers with access to a single field and Enterprise customers).

Was this helpful?