[ Web Proxy ]
URL:
Viewing: https://blog.cloudflare.com/tag/waf-rules/ [Back]  [Original]

Posts tagged "WAF Rules" Cloudflare Blog Skip to content
March 4, 2026

Always-on detections: eliminating the WAF log versus block trade-off

Cloudflare is introducing Attack Signature Detection and Full-Transaction Detection to provide continuous, high-fidelity security insights without the manual tuning of traditional WAFs. By correlating request payloads with server responses, we can now identify successful exploits and data exfiltration while minimizing false positives.

March 7, 2024

General availability for WAF Content Scanning for file malware protection

Announcing the General Availability of WAF Content Scanning, protecting your web applications and APIs from malware by scanning files in-transit

January 23, 2024

How Cloudflares AI WAF proactively detected the Ivanti Connect Secure critical zero-day vulnerability

The issuance of Emergency Rules by Cloudflare on January 17, 2024, helped give customers a big advantage in dealing with these threats

December 15, 2021

Protection against CVE-2021-45046, the additional Log4j RCE vulnerability

This vulnerability is actively being exploited and anyone using Log4J should update to version 2.16.0 as soon as possible. Latest version is available on the Log4J download page.

December 10, 2021

Inside the Log4j2 vulnerability (CVE-2021-44228)

In this post we explain the history of this vulnerability, how it was introduced, how Cloudflare is protecting our clients. We will update later with actual attempted exploitation we are seeing blocked by our firewall service.

December 10, 2021

CVE-2021-44228 - Log4j RCE 0-day mitigation

A zero-day exploit affecting the popular Apache Log4j utility (CVE-2021-44228) was made public on December 9, 2021, that results in remote code execution (RCE).

December 3, 2021

Get notified when your site is under attack

Cloudflare can now send proactive notifications about any application security event spike, so you are warned whenever an attack might be targeting your application.

October 8, 2021

Helping Apache Servers stay safe from zero-day path traversal attacks (CVE-2021-41773)

On September 29th 2021, the Apache Security team was alerted of a path traversal vulnerability being actively exploited (zero-day) against Apache HTTP Server version 2.4.49. Customers running the affected Apache version, should update to 2.5.51 as soon as possible.

September 8, 2021

How Cloudflare helped mitigate the Atlassian Confluence OGNL vulnerability before the PoC was released

On August 25, 2021, Atlassian released a security advisory affecting their Confluence application. The Cloudflare WAF soon after started mitigating an increase in malicious traffic to vulnerable endpoints ensuring customers remained protected.

July 1, 2021

Account Takeover Protection and WAF mitigations to help stop Global Brute Force Campaigns

Today, we are making our Account Takeover Protection capabilities available to all paid plans at no additional charge.

March 7, 2021

Protecting against recently disclosed Microsoft Exchange Server vulnerabilities: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065

Cloudflare has deployed managed rules protecting customers against a series of remotely exploitable vulnerabilities that were recently found in Microsoft Exchange Server.

February 19, 2021

Using HPKE to Encrypt Request Payloads

Allowing users to securely log parts of the request that match firewall rules while making it impossible for anyone else to decrypt.

December 11, 2020

Encrypting your WAF Payloads with Hybrid Public Key Encryption (HPKE)

Allowing logging for payloads that trigger the Web Application Firewall has always led to end-user privacy concerns. We built encrypted matched payload logging to solve this!

July 7, 2020

CVE-2020-5902: Helping to protect against the F5 TMUI RCE vulnerability

Cloudflare has deployed a new managed rule protecting customers against a remote code execution vulnerability that has been found in F5 BIG-IPs web-based Traffic Management User Interface (TMUI).

March 5, 2019

Stopping Drupals SA-CORE-2019-003 Vulnerability

Drupal discovered a severe vulnerability and said they would release a patch. When the patch was released we analysed and created rules to mitigate these. By analysing the patch we created WAF rules to protect Cloudflare customers running Drupal.

October 3, 2018

Announcing Firewall Rules

Threat landscapes change every second. As attackers evolve, vulnerabilities materialise faster than engineers can patch systems becoming more dynamic and devious. Part of Cloudflares mission is to keep you and your applications safe.

April 20, 2018

Keeping Drupal sites safe with Cloudflare's WAF

Cloudflares team of security analysts monitor for upcoming threats and vulnerabilities and where possible put protection in place for upcoming threats before they compromise our customers.

March 29, 2018

Cloudflare is adding Drupal WAF Rule to Mitigate Critical Drupal Exploit

Drupal has recently announced an update to fix a critical remote code execution exploit (SA-CORE-2018-002/CVE-2018-7600). This patch is to disallow forms and form fields from starting with the # character.

Load more

Your email address:

Web Proxy Viewer  |  New URL  |  Original Page