Summary
Cloudflare's August 4, 2026 WAF managed-ruleset release added new detections for Microsoft SharePoint and Ruby on Rails vulnerabilities and strengthened SSRF cloud-metadata protection. A follow-on release scheduled for August 10 adds coverage for a vBulletin RCE and version-control information disclosure.
What changed
The 2026-08-04 WAF managed ruleset shipped new rules targeting Microsoft SharePoint and Rails vulnerabilities and enhanced protection against server-side request forgery (SSRF) toward cloud metadata endpoints. A scheduled 2026-08-10 release will add vBulletin RCE and version-control information-disclosure rules.
Why it matters
Managed WAF ruleset updates are how most Cloudflare customers get virtual patching before they can update affected software. Bundling SharePoint, Rails, and SSRF coverage in one release reflects the active exploitation windows enterprises face and reduces exposure without app-side changes.
Evidence excerpt
New security rules were added for Microsoft SharePoint and Rails vulnerabilities, with enhanced SSRF cloud protection capabilities.