WAF – WAF Release – 2025-09-26

WAF – WAF Release – 2025-09-26

Managed Ruleset Updated

This update introduces 11 new detections in the Cloudflare Managed Ruleset (all currently set to Disabled mode to preserve remediation logic and allow quick activation if needed). The rules cover a broad spectrum of threats – SQL injection techniques, command and code injection, information disclosure of common files, URL anomalies, and cross-site scripting.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset3ffd242b4ba242ca965022d3a67d8561 100859ASQLi – UNION – 3N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset91d9cf56355b4ab88481b2fd4de80468 100889Command Injection – Generic 9N/ADisabledThis is a New Detection
Cloudflare Managed Rulesetc15ca8e8290f485287037665f2be3ddf 100890Information Disclosure – Common Files – 2N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset56669615f2984c2cac8c608980a252a8 100891Anomaly:URL – Relative PathsN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetc41789fb6370431d809567d17e7d3865 100894XSS – Inline FunctionN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetb995d0b930604fa6b8d9b2a13792565c 100895XSS – DOMN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetab8277e3f432400bbd9403dd42978e38 100896SQLi – MSSQL Length EnumerationN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset3ec33bc5ac77495a9f55020e3ab43f7e 100897Generic Rules – Code Injection – 3N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset4375dc90c7af4c55908f6b95c1686741 100898SQLi – EvasionN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset945c5aa9f45141dd872d7ec920999be0 100899SQLi – Probing 2N/ADisabledThis is a New Detection
Cloudflare Managed Ruleset2c20b5e8684043f48620ff77b4026c88 100900SQLi – ProbingN/ADisabledThis is a New Detection

Source: Cloudflare



Latest Posts

Pass It On
Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *