Summary

On July 29, 2026, Cloudflare shipped a WAF Managed Ruleset update adding new protections against a Nuxt Server Island remote code execution vulnerability and Alibaba Fastjson deserialization flaws, along with enhanced SSRF and command-injection detection. Several rules moved from Log to Block by default, so the new coverage actively blocks matching traffic rather than only recording it.

What changed

Cloudflare's WAF Managed Ruleset (changelog dated 2026-07-29) added detections for Nuxt Server Island RCE and Fastjson deserialization, strengthened SSRF/command-injection rules, and shifted multiple rules from Log to Block.

Why it matters

Server-side JavaScript frameworks like Nuxt and widely embedded libraries like Fastjson sit inside many AI-app and API backends, so a managed edge rule that blocks these classes of RCE/deserialization the same week disclosures circulate gives teams virtual-patching coverage before they can redeploy. The Log-to-Block promotion means protection is on by default, not opt-in.

Evidence excerpt

New protections for Nuxt Server Island RCE and Alibaba Fastjson deserialization vulnerabilities, plus enhanced SSRF/command injection detection, with multiple ruleset updates shifting from Log to Block actions.

Sources