Cloudflare announced a Web Application Firewall (WAF) release on August 25 2026. The update makes four previously logged detections enforceable by blocking traffic:
- HTTP/2 Request Smuggling – Request Body Anomaly
- XSS – JavaScript Event Handler Coercion – Headers
- XSS – JavaScript Event Handler Coercion – Body
- XSS – JavaScript Event Handler Coercion – URI
The vendor also merged the beta rule “XSS, HTML Injection – Script Tag – Beta” into the stable “XSS, HTML Injection – Script Tag” rule, simplifying rule management.
Additionally, a new Generic Rules detection for Remote Code Execution was introduced in Block mode, providing immediate protection against a broad class of exploitation attempts.
These changes are part of Cloudflare’s Managed Ruleset and are intended to reduce false‑negative exposure while keeping the false‑positive rate low. Users can review the updated rule IDs in the Cloudflare dashboard.